Evaluating and enhancing the robustness of vision transformers against adversarial attacks in medical imaging

被引:1
|
作者
Kanca, Elif [1 ]
Ayas, Selen [2 ]
Kablan, Elif Baykal [1 ]
Ekinci, Murat [2 ]
机构
[1] Karadeniz Tech Univ, Dept Software Engn, Trabzon, Turkiye
[2] Karadeniz Tech Univ, Dept Comp Engn, Trabzon, Turkiye
关键词
Adversarial attacks; Adversarial defense; Vision transformer; Medical image classification; DIABETIC-RETINOPATHY; VALIDATION;
D O I
10.1007/s11517-024-03226-5
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
Deep neural networks (DNNs) have demonstrated exceptional performance in medical image analysis. However, recent studies have uncovered significant vulnerabilities in DNN models, particularly their susceptibility to adversarial attacks that manipulate these models into making inaccurate predictions. Vision Transformers (ViTs), despite their advanced capabilities in medical imaging tasks, have not been thoroughly evaluated for their robustness against such attacks in this domain. This study addresses this research gap by conducting an extensive analysis of various adversarial attacks on ViTs specifically within medical imaging contexts. We explore adversarial training as a potential defense mechanism and assess the resilience of ViT models against state-of-the-art adversarial attacks and defense strategies using publicly available benchmark medical image datasets. Our findings reveal that ViTs are vulnerable to adversarial attacks even with minimal perturbations, although adversarial training significantly enhances their robustness, achieving over 80% classification accuracy. Additionally, we perform a comparative analysis with state-of-the-art convolutional neural network models, highlighting the unique strengths and weaknesses of ViTs in handling adversarial threats. This research advances the understanding of ViTs robustness in medical imaging and provides insights into their practical deployment in real-world scenarios.Graphical Abstract(left).
引用
收藏
页码:673 / 690
页数:18
相关论文
共 50 条
  • [21] Enhancing EEG Signal Classifier Robustness Against Adversarial Attacks Using a Generative Adversarial Network Approach
    Aissa N.E.H.S.B.
    Kerrache C.A.
    Korichi A.
    Lakas A.
    Belkacem A.N.
    IEEE Internet of Things Magazine, 2024, 7 (03): : 44 - 49
  • [22] On the robustness of skeleton detection against adversarial attacks
    Bai, Xiuxiu
    Yang, Ming
    Liu, Zhe
    NEURAL NETWORKS, 2020, 132 : 416 - 427
  • [23] ROBUSTNESS OF SAAK TRANSFORM AGAINST ADVERSARIAL ATTACKS
    Ramanathan, Thiyagarajan
    Manimaran, Abinaya
    You, Suya
    Kuo, C-C Jay
    2019 IEEE INTERNATIONAL CONFERENCE ON IMAGE PROCESSING (ICIP), 2019, : 2531 - 2535
  • [24] Robustness Against Adversarial Attacks Using Dimensionality
    Chattopadhyay, Nandish
    Chatterjee, Subhrojyoti
    Chattopadhyay, Anupam
    SECURITY, PRIVACY, AND APPLIED CRYPTOGRAPHY ENGINEERING, SPACE 2021, 2022, 13162 : 226 - 241
  • [25] Enhancing Robustness of Weather Removal: Preprocessing-Based Defense Against Adversarial Attacks
    Frants, Vladimir
    Agaian, Sos
    MULTIMODAL IMAGE EXPLOITATION AND LEARNING 2024, 2024, 13033
  • [26] Enhancing robustness of person detection: A universal defense filter against adversarial patch attacks
    Mao, Zimin
    Chen, Shuiyan
    Miao, Zhuang
    Li, Heng
    Xia, Beihao
    Cai, Junzhe
    Yuan, Wei
    You, Xinge
    COMPUTERS & SECURITY, 2024, 146
  • [27] Understanding Adversarial Robustness of Vision Transformers via Cauchy Problem
    Wang, Zheng
    Ruan, Wenjie
    MACHINE LEARNING AND KNOWLEDGE DISCOVERY IN DATABASES, ECML PKDD 2022, PT III, 2023, 13715 : 562 - 577
  • [28] Adversarial Robustness of Vision Transformers Versus Convolutional Neural Networks
    Ali, Kazim
    Bhatti, Muhammad Shahid
    Saeed, Atif
    Athar, Atifa
    Al Ghamdi, Mohammed A.
    Almotiri, Sultan H.
    Akram, Samina
    IEEE ACCESS, 2024, 12 : 105281 - 105293
  • [29] Towards Evaluating Adversarial Attacks Robustness in Wireless Communication
    Ftaimi, Asmaa
    Mazri, Tomader
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2021, 12 (06) : 639 - 646
  • [30] Transferable Adversarial Attacks on Vision Transformers with Token Gradient Regularization
    Zhang, Jianping
    Huang, Yizhan
    Wu, Weibin
    Lyu, Michael R.
    2023 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION (CVPR), 2023, : 16415 - 16424