arXiv:2501.01908cs.CVcs.LG2025-01被引 2

无需重训练即可防御MRI重建模型的对抗攻击

Training-Free Adversarial Robustness in Computational MRI

  • 利用循环测量一致性设计免重训防御机制
  • 在多种数据集和攻击强度下显著降低图像失真
  • 适用于盲区防御与自适应攻击场景,实用性强

深度学习方法已成为重构欠采样磁共振成像(MRI)数据的主流技术。然而研究表明,这些方法对微小的对抗输入扰动敏感,导致输出图像出现严重失真。现有缓解策略大多需重新训练模型。本文提出一种无需重训练的新型防御方法,基于循环测量一致性思想,在攻击输入附近的小球内最小化新的缓解目标。实验表明,该方法在多种数据集、攻击类型与强度以及PD-DL网络上均显著降低对抗扰动的影响,定性与定量表现均优于传统方法。此外,我们引入一个贴近实际的弱对抗扰动场景,模拟原始数据中的脉冲噪声,与条纹伪影相关,并验证了该方法在此设置下的有效性。最后,证明该方法在两种现实扩展场景中依然有效:盲设场景(用户未知攻击强度或算法)与自适应攻击场景(攻击者掌握防御策略)。

原文摘要 · Abstract (English)

Deep learning (DL) methods have become the state-of-the-art for reconstructing sub-sampled magnetic resonance imaging (MRI) data. However, studies have shown that these methods are susceptible to small adversarial input perturbations, resulting in major distortions in the output images. Various strategies have been proposed to reduce the effects of these attacks, but they require retraining. In this work, we propose a novel approach for mitigating adversarial attacks on MRI reconstruction models without any retraining. Based on the idea of cyclic measurement consistency, we devise a novel mitigation objective that is minimized in a small ball around the attack input. Results show that our method substantially reduces the impact of adversarial perturbations across different datasets, attack types/strengths and PD-DL networks, and qualitatively and quantitatively outperforms conventional mitigation methods. We also introduce a practically relevant scenario for small adversarial perturbations that models impulse noise in raw data, which relates to herringbone artifacts, and show the applicability of our approach in this setting. Finally, we show our mitigation approach remains effective in two realistic extension scenarios: a blind setup, where the attack strength or algorithm is not known to the user; and an adaptive attack setup, where the attacker has full knowledge of the defense strategy.

MRI重建对抗鲁棒性免重训练医学图像

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。