发现病理模型对微小扰动极度敏感,0.1%像素噪声可致诊断准确率下降20%。
The Butterfly Effect in Pathology: Exploring Security in Pathology Foundation Models
- 提出无标签攻击框架,仅用局部扰动实现全局破坏。
- 在五数据集六任务上验证,0.1%切片扰动致精度最高降20%。
- 揭示切片语义内容与脆弱性关联,为防御提供依据。
随着病理基础模型在科研和临床决策支持系统中的广泛应用,其安全性成为关键问题。然而,这些模型对对抗攻击的脆弱性仍缺乏系统研究。本文首次针对全切片图像(WSI)分析中的病理基础模型开展系统性安全评估。我们提出‘局部扰动、全局影响’原则,设计无需下游标签的无标签攻击框架,并基于WSI特性重新定义扰动预算。通过改进四种经典白盒攻击方法,在三个代表性病理基础模型上跨五数据集、六下游任务进行实验。结果表明,仅修改每张切片0.1%的切片块且加入不可察觉的噪声,即可导致下游准确率最高下降20%。进一步分析了影响攻击成功的关键因素,探究了切片级脆弱性与语义内容的关系,并初步探索防御策略。这些发现为病理基础模型的对抗鲁棒性与可靠部署奠定基础。代码已公开:https://github.com/Jiashuai-Liu-hmos/Attack-WSI-pathology-foundation-models。
原文摘要 · Abstract (English)
With the widespread adoption of pathology foundation models in both research and clinical decision support systems, exploring their security has become a critical concern. However, despite their growing impact, the vulnerability of these models to adversarial attacks remains largely unexplored. In this work, we present the first systematic investigation into the security of pathology foundation models for whole slide image~(WSI) analysis against adversarial attacks. Specifically, we introduce the principle of \textit{local perturbation with global impact} and propose a label-free attack framework that operates without requiring access to downstream task labels. Under this attack framework, we revise four classical white-box attack methods and redefine the perturbation budget based on the characteristics of WSI. We conduct comprehensive experiments on three representative pathology foundation models across five datasets and six downstream tasks. Despite modifying only 0.1\% of patches per slide with imperceptible noise, our attack leads to downstream accuracy degradation that can reach up to 20\% in the worst cases. Furthermore, we analyze key factors that influence attack success, explore the relationship between patch-level vulnerability and semantic content, and conduct a preliminary investigation into potential defence strategies. These findings lay the groundwork for future research on the adversarial robustness and reliable deployment of pathology foundation models. Our code is publicly available at: https://github.com/Jiashuai-Liu-hmos/Attack-WSI-pathology-foundation-models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。