arXiv:2604.22579eess.IVcs.CV2026-04中稿 · The IEEE Internati…

医学影像模型常依赖易被干扰的非鲁棒特征,影响泛化能力。

Useful nonrobust features are ubiquitous in biomedical images

论文配图:Useful nonrobust features are ubiquitous in biomedical images
图 1 · 摘自论文原文
  • 通过对抗训练分离出非鲁棒与鲁棒特征,验证其预测价值。
  • 仅用非鲁棒特征在五项MedMNIST任务上达显著高于随机水平的准确率。
  • 适合标准环境部署,但需权衡对分布外数据的脆弱性。

我们研究了医学影像深度网络是否学习到有用的非鲁棒特征——即不可解释且极易受微小对抗扰动影响的预测性输入模式——以及这些特征如何影响测试性能。结果表明,仅在非鲁棒特征上训练的模型在五个MedMNIST分类任务中均达到显著高于随机水平的准确率,证实其在分布内具有预测价值。相反,主要依赖鲁棒特征的对抗训练模型虽在分布内准确率下降,但在受控分布偏移(MedMNIST-C)下表现明显更优。这揭示了医学影像分类中存在实际的鲁棒性-准确率权衡,应根据部署场景需求进行调整。

原文摘要 · Abstract (English)

We study whether deep networks for medical imaging learn useful nonrobust features - predictive input patterns that are not human interpretable and highly susceptible to small adversarial perturbations - and how these features impact test performance. We show that models trained only on nonrobust features achieve well above chance accuracy across five MedMNIST classification tasks, confirming their predictive value in-distribution. Conversely, adversarially trained models that primarily rely on robust features sacrifice in-distribution accuracy but yield markedly better performance under controlled distribution shifts (MedMNIST-C). Overall, nonrobust features boost standard accuracy yet degrade out-of-distribution performance, revealing a practical robustness-accuracy trade-off in medical imaging classification tasks that should be tailored to the requirements of the deployment setting.

医学影像鲁棒性特征分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。