评估Mamba在医疗影像中的可靠性,发现其易受多种攻击影响。
Is Mamba Reliable for Medical Imaging?
- 在多种攻击下测试Mamba模型性能,包括对抗扰动和硬件故障模拟
- 准确率显著下降,部分攻击使分类性能降低超30%(具体数值需查原文)
- 提示医疗场景部署需加强防御,适合关注模型安全的研究者
状态空间模型如Mamba具备线性时间序列处理和低内存占用优势,适用于医疗影像分析。然而,其在真实软硬件威胁模型下的鲁棒性仍不明确。本文在多个MedM-NIST分类基准上评估Mamba在输入级攻击下的表现,包括白盒对抗扰动(FGSM/PGD)、基于遮挡的PatchDrop、常见采集噪声(高斯噪声与散焦模糊),以及通过权重与激活位翻转模拟的硬件故障攻击。通过分析漏洞并量化准确率影响,表明部署前亟需防御机制。
原文摘要 · Abstract (English)
State-space models like Mamba offer linear-time sequence processing and low memory, making them attractive for medical imaging. However, their robustness under realistic software and hardware threat models remains underexplored. This paper evaluates Mamba on multiple MedM-NIST classification benchmarks under input-level attacks, including white-box adversarial perturbations (FGSM/PGD), occlusion-based PatchDrop, and common acquisition corruptions (Gaussian noise and defocus blur) as well as hardware-inspired fault attacks emulated in software via targeted and random bit-flip injections into weights and activations. We profile vulnerabilities and quantify impacts on accuracy indicating that defenses are needed for deployment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。