Adversarial Medical Image with Hierarchical Feature Hiding
IEEE Transactions on Medical Imaging
|November 23, 2023
Summary
Adversarial examples (AEs) in medical imaging are vulnerable. A new Hierarchical Feature Constraint (HFC) method effectively hides these AEs, bypassing current detection methods and highlighting flaws in reactive defenses.
Area of Science:
- Medical Imaging
- Deep Learning Security
- Computer Vision
Background:
- Deep learning models for medical images are susceptible to adversarial examples (AEs), creating security risks in clinical settings.
- Conventional adversarial attacks (e.g., PGD) create detectable outliers in the feature space, allowing for effective reactive defenses.
Purpose of the Study:
- To investigate the characteristics of conventional medical AEs and reassess the reliability of existing reactive defenses.
- To develop a novel method for generating more stealthy adversarial examples in medical imaging.
Main Methods:
- Theoretical proof showing conventional attacks optimize features in a fixed direction, creating outlier representations.
- A stress test comparing the vulnerability of medical images to natural images.
- Proposal of Hierarchical Feature Constraint (HFC), an add-on to white-box attacks to embed AEs within the target feature distribution.
Main Results:
- Medical images exhibit a unique vulnerability exploitable for hiding AEs.
- The proposed HFC method successfully hides adversarial features, bypassing state-of-the-art medical AE detectors.
- HFC outperforms competing adaptive attacks in evading detection across diverse medical datasets (2D/3D, multiple modalities).
Conclusions:
- Conventional reactive defenses against medical AEs are insufficient due to the distinct characteristics of these attacks.
- The HFC method demonstrates a significant advancement in generating stealthy adversarial examples for medical imaging.
- Findings underscore the need for developing more robust and adaptive defense strategies against sophisticated adversarial attacks in healthcare AI.


