arXiv:2411.00837cs.CVcs.AI2024-11

针对乳腺癌纵向影像诊断模型,提出新型对抗攻击方法。

Longitudinal Mammogram Exam-based Breast Cancer Diagnosis Models: Vulnerability to Adversarial Attacks

  • 利用连续影像间的特征关联设计攻击,结合交叉熵与距离度量学习。
  • 在590例患者数据上,使模型误判率超现有攻击方法,且对防御训练仍有效。
  • 适用于评估医疗影像模型安全性,尤其关注纵向分析场景的可信度。

在乳腺癌检测与诊断中,对乳腺钼靶影像进行纵向分析至关重要。当前模型能有效捕捉序列影像中的时序特征变化,从而提升学习效果。然而,这些纵向模型对对抗攻击的鲁棒性尚未被充分研究。本研究提出一种新型攻击方法,利用纵向模型中两次连续乳腺钼靶影像间的特征级关系,结合交叉熵损失与距离度量学习,在黑盒攻击场景下实现高效攻击。我们在包含590名乳腺癌患者(每人有两次连续钼靶检查)的病例对照数据集上进行了实验。结果表明,该方法在诱导诊断模型输出相反结论方面显著优于多种主流对抗攻击方法,且即使在模型采用对抗训练防御的情况下依然有效。

原文摘要 · Abstract (English)

In breast cancer detection and diagnosis, the longitudinal analysis of mammogram images is crucial. Contemporary models excel in detecting temporal imaging feature changes, thus enhancing the learning process over sequential imaging exams. Yet, the resilience of these longitudinal models against adversarial attacks remains underexplored. In this study, we proposed a novel attack method that capitalizes on the feature-level relationship between two sequential mammogram exams of a longitudinal model, guided by both cross-entropy loss and distance metric learning, to achieve significant attack efficacy, as implemented using attack transferring in a black-box attacking manner. We performed experiments on a cohort of 590 breast cancer patients (each has two sequential mammogram exams) in a case-control setting. Results showed that our proposed method surpassed several state-of-the-art adversarial attacks in fooling the diagnosis models to give opposite outputs. Our method remained effective even if the model was trained with the common defending method of adversarial training.

医学影像对抗攻击纵向分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。