用博弈论设计防御策略,让医疗影像模型更抗攻击。
Game-Theoretic Defenses for Robust Conformal Prediction Against Adversarial Attacks in Medical Imaging
- 构建对抗攻击下的鲁棒置信区间,结合博弈论优化防御。
- 在多个医学数据集上保持高覆盖率,同时缩小预测集合大小。
- 适合关注模型安全的医疗AI研究者与临床部署人员。
对抗攻击对深度学习模型的可靠性与安全性构成重大威胁,尤其在医疗影像等关键领域。本文提出一种新框架,将置信预测与博弈论防御策略结合,提升模型对已知及未知对抗扰动的鲁棒性。针对三个核心问题:在已知攻击下构建有效且高效的置信预测集(RQ1),通过保守阈值确保未知攻击下的覆盖率(RQ2),以及在零和博弈框架中确定最优防御策略(RQ3)。方法包括训练针对特定攻击类型的专用防御模型,并使用最大/最小分类器有效聚合防御。在MedMNIST数据集(PathMNIST、OrganAMNIST、TissueMNIST)上的大量实验表明,该方法在保持高覆盖率的同时显著缩小预测集规模。博弈分析显示,最优防御策略常收敛至单一鲁棒模型,在所有评估数据集上优于均匀与简单策略。本工作推进了不确定性量化与对抗鲁棒性的前沿,为对抗环境下深度学习模型的可靠部署提供保障。
原文摘要 · Abstract (English)
Adversarial attacks pose significant threats to the reliability and safety of deep learning models, especially in critical domains such as medical imaging. This paper introduces a novel framework that integrates conformal prediction with game-theoretic defensive strategies to enhance model robustness against both known and unknown adversarial perturbations. We address three primary research questions: constructing valid and efficient conformal prediction sets under known attacks (RQ1), ensuring coverage under unknown attacks through conservative thresholding (RQ2), and determining optimal defensive strategies within a zero-sum game framework (RQ3). Our methodology involves training specialized defensive models against specific attack types and employing maximum and minimum classifiers to aggregate defenses effectively. Extensive experiments conducted on the MedMNIST datasets, including PathMNIST, OrganAMNIST, and TissueMNIST, demonstrate that our approach maintains high coverage guarantees while minimizing prediction set sizes. The game-theoretic analysis reveals that the optimal defensive strategy often converges to a singular robust model, outperforming uniform and simple strategies across all evaluated datasets. This work advances the state-of-the-art in uncertainty quantification and adversarial robustness, providing a reliable mechanism for deploying deep learning models in adversarial environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。