arXiv:2601.07056cs.CVcs.AI2026-01

针对医学高光谱成像,提出能精准干扰肿瘤区域的对抗攻击方法。

Adversarial Attacks on Medical Hyperspectral Imaging Exploiting Spectral-Spatial Dependencies and Multiscale Features

  • 基于局部光谱-空间依赖与多尺度特征构建结构化攻击框架
  • 在脑部和胆管数据集上显著降低关键肿瘤区分类准确率
  • 生成符合解剖结构的微小扰动,适合用于模型防御训练

医学高光谱成像(MHSI)通过捕捉组织的光谱-空间信息,在疾病诊断中展现出巨大潜力。尽管深度学习显著提升了MHSI分类精度,但其鲁棒性受限于深度神经网络中精度与鲁棒性的经典权衡问题。这一缺陷在MHSI中尤为关键,因可靠预测依赖于局部组织关系及多尺度光谱-空间结构。提升鲁棒性的有效途径是识别最不稳定的对抗样本并用于对抗训练。然而,现有攻击方法未能充分挖掘MHSI特有的属性,导致攻击效果不足,难以支撑鲁棒性增强。为此,本文提出一种结构化的对抗攻击框架,逐步建模局部光谱-空间依赖与多尺度层次化表示。该方法通过建模邻域依赖与层次化光谱-空间特征,生成解剖学上一致的扰动。在脑部和胆管数据集上的实验表明,该方法比现有基线更有效地削弱关键肿瘤区域的病变分类性能,同时保持较低的扰动幅度。结果揭示了当前MHSI模型存在临床相关的鲁棒性弱点,并提供了更强的对抗样本以支持针对性防御策略的开发。

原文摘要 · Abstract (English)

Medical hyperspectral imaging (MHSI) has shown strong potential for disease diagnosis by capturing spectral-spatial information of tissues. While deep learning has substantially improved MHSI classification accuracy, its robustness remains limited due to the well-known trade-off between accuracy and robustness in Deep Neural Networks (DNNs). This issue is particularly critical in MHSI, where reliable prediction depends on local tissue relationships and multiscale spectral-spatial structures. A practical way to improve robustness is to identify the most unstable adversarial examples and incorporate them into adversarial training. However, existing attack methods do not sufficiently exploit these MHSI-specific properties, leading to suboptimal attack effectiveness and limited value for robustness enhancement. To address this gap, we propose a structured adversarial attack framework for MHSI that progressively models its local spectral-spatial dependencies and multiscale hierarchical representations. The proposed method generates anatomically consistent perturbations by modeling neighborhood dependencies and hierarchical spectral-spatial features. Experiments on the brain and choledoch datasets show that our method more effectively degrades lesion-related classification performance in critical tumor regions than existing baselines while maintaining low perturbation magnitude. These results reveal a clinically relevant robustness weakness in current MHSI models and provide stronger adversarial samples for developing targeted defense strategies.

医学影像对抗攻击高光谱成像

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。