Related Experiment Video
Updated: Aug 14, 2026

A Cognitive Fusion-guided Prostate Biopsy Using Multiparametric Magnetic Resonance Imaging and Transrectal Ultrasound
Published on: March 21, 2025
Anatomical Prior-Guided Black-Box Attack Optimization for Prostate Tumor mpMRI Classification Models
Abstract:
Prostate cancer is a highly prevalent malignancy, and deep learning has significantly advanced di agnostic models based on multi-parametric MRI (mpMRI). However, the robustness of these models is threatened by adversarial attacks, potentially leading to fatal misdiagnoses and impeding clinical translation. Unlike natural images, the vulnerability of medical images lies within anatomical details and multi-modal variations, creating an "efficiency-imperceptibility" dilemma for existing black-box attacks. Low-precision strategies (e.g., Square Attack, sign Hunter) lack fine-grained anatomical awareness, introducing redundancy in non-critical areas, while high-precision strategies (e.g., NES, ZOO) suffer from prohibitive query costs due to vast search spaces. To address this, we pro pose an Anatomical Prior-Guided black-box optimization method. By integrating mpMRI Regions of Interest (ROI) with model sensitivity analysis via local finite difference probing, we construct a dynamic weight map to quantify decision responses. This constrains the optimization to diagnostically critical high-frequency regions, specifically enhancing high-precision strategies to generate minute yet disruptive perturbations. Experiments on multiple prostate mpMRI datasets demonstrate that our method reduces query overhead by 40%-70% and pixel modification count (L0 norm) by over 40%. This study confirms the pivotal role of anatomical priors, offering a novel paradigm for balancing attack imperceptibility with efficiency and pro viding a low-resource framework for evaluating medical AI robustness. The project code will be made publicly available upon acceptance.
Insights
We developed an anatomical prior-guided method to improve adversarial attack efficiency on prostate cancer deep learning models. This approach enhances robustness against attacks by focusing on critical diagnostic regions in MRI scans.
Area of Science:
- Medical Imaging AI
- Machine Learning Security
- Oncology Diagnostics
Background:
- Deep learning models for prostate cancer diagnosis using multi-parametric MRI (mpMRI) are advanced but vulnerable to adversarial attacks.
- Adversarial attacks on medical images face an efficiency-imperceptibility dilemma due to anatomical details and multi-modal variations.
- Existing black-box attacks are either imprecise or computationally expensive, hindering clinical translation of AI models.
Purpose of the Study:
- To propose a novel black-box optimization method that enhances the efficiency and imperceptibility of adversarial attacks on medical AI.
- To address the limitations of existing adversarial attack strategies in the context of medical imaging.
- To develop a robust framework for evaluating the security of AI models in clinical settings.
Main Methods:
- Anatomical Prior-Guided black-box optimization integrating mpMRI Regions of Interest (ROI).
- Utilizing local finite difference probing for model sensitivity analysis to create a dynamic weight map.
- Constraining optimization to diagnostically critical high-frequency regions for targeted perturbations.
Main Results:
- Reduced query overhead by 40%-70% compared to existing methods.
- Decreased pixel modification count (L0 norm) by over 40%.
- Demonstrated effective generation of minute yet disruptive perturbations in prostate mpMRI datasets.
Conclusions:
- Anatomical priors play a crucial role in balancing attack imperceptibility and efficiency for medical AI.
- The proposed method offers a low-resource framework for evaluating the robustness of medical AI against adversarial attacks.
- This research provides a new paradigm for securing AI diagnostic tools in healthcare.