Related Experiment Video
Updated: Nov 22, 2025

04:48
Application of Deep Learning-Based Medical Image Segmentation via Orbital Computed Tomography
Published on: November 30, 2022
3.1K
Universal adversarial attacks on deep neural networks for medical image classification
Hokuto Hirano1, Akinori Minagi1, Kazuhiro Takemoto2
1Department of Bioscience and Bioinformatics, Kyushu Institute of Technology, Iizuka, Fukuoka, 820-8502, Japan.
BMC Medical Imaging
|January 8, 2021
Summary
Deep neural networks (DNNs) are vulnerable to universal adversarial perturbations (UAPs), posing risks to medical image classification. Adversarial retraining offered limited defense, highlighting the need for robust security in AI-driven diagnostics.
Area of Science:
- Artificial Intelligence
- Medical Imaging
- Cybersecurity
Background:
- Deep neural networks (DNNs) are crucial for automated clinical diagnosis via medical image classification.
- Evaluating DNN robustness against adversarial attacks is vital due to high-stakes medical decisions.
- Previous research on simple adversarial attacks is insufficient; vulnerability to Universal Adversarial Perturbations (UAPs) remains underexplored.
Purpose of the Study:
- To investigate the vulnerability of DNNs in medical image classification to Universal Adversarial Perturbations (UAPs).
- To assess DNN performance across three distinct medical classification tasks: skin cancer, diabetic retinopathy, and pneumonia.
- To evaluate the impact of UAPs on seven different DNN model architectures.
Main Methods:
- Focused on three representative DNN-based medical image classification tasks.
- Investigated vulnerability against seven model architectures of Universal Adversarial Perturbations (UAPs).
Main Results:
- DNNs demonstrated significant vulnerability to both non-targeted and targeted UAPs, achieving over 80% success rates.
- Model architecture had minimal impact on DNN vulnerability to UAPs.
- Adversarial retraining proved effective in only a few cases for enhancing robustness against UAPs.
Conclusions:
- DNN-based clinical diagnosis systems are more susceptible to adversarial attacks than previously assumed.
- Adversaries can compromise diagnostic accuracy with lower costs and without data distribution considerations.
- Current adversarial defense strategies may have limitations, necessitating careful development and application of DNNs in medical imaging.