Related Experiment Video
Updated: Sep 7, 2025

04:48
Application of Deep Learning-Based Medical Image Segmentation via Orbital Computed Tomography
Published on: November 30, 2022
2.9K
Digital Watermarking as an Adversarial Attack on Medical Image Analysis with Deep Learning
Kyriakos D Apostolidis1, George A Papakostas1
1MLV Research Group, Department of Computer Science, International Hellenic University, 65404 Kavala, Greece.
Journal of Imaging
|June 23, 2022
Summary
Digital watermarking can act as a black-box adversarial attack, significantly degrading the performance of computer vision models in medical image analysis. This study demonstrates watermarking attacks reduce accuracy by over 50% on models like MobileNetV2.
Area of Science:
- Computer Vision
- Medical Image Analysis
- Deep Learning
Background:
- Deep Neural Networks (DNNs) are widely used in Computer Vision (CV).
- Adversarial attacks pose a significant threat to the performance of CV models, especially in Medical Image Analysis.
- Digital watermarking is typically used for security but can be repurposed.
Purpose of the Study:
- To investigate digital watermarking as a novel black-box adversarial attack, termed 'watermarking attacks'.
- To assess the impact of these watermarking attacks on the performance of state-of-the-art CV models used for medical image analysis.
- To identify the most vulnerable models and medical imaging modalities.
Main Methods:
- A moment-based local image watermarking method was implemented.
- The method was applied to three medical imaging modalities: Magnetic Resonance Images (MRI), Computed Tomography (CT-scans), and X-ray images.
- The attacks were tested against three CV models: DenseNet 201, DenseNet 169, and MobileNetV2.
Main Results:
- The watermarking attacks caused over 50% degradation in model accuracy.
- MobileNetV2 demonstrated the highest vulnerability to the proposed attacks.
- CT-scans experienced the most significant performance reduction among the tested modalities.
Conclusions:
- Digital watermarking presents a viable and potent adversarial attack vector against CV models in medical imaging.
- The widespread use of watermarks for security may inadvertently introduce substantial risks to AI-driven vision systems.
- Further research is needed to develop robust defenses against such watermarking attacks.

