Szczegóły publikacji
Opis bibliograficzny
Robust detection of directional adversarial attacks in Deep Neural Networks for radiological imaging / Tristan MALATYŃSKI, Joanna JAWOREK-KORJAKOWSKA // W: CVPR 2026 [Dokument elektroniczny] : IEEE/CVF Computer Vision and Pattern Recognition : 3-7 June 2026, Denver, [USA] : proceedings. — Wersja do Windows. — Dane tekstowe. — [Denver] : Computer Vision Foundation, [2026]. — S. 4240–4249. — Wymagania systemowe: Adobe Reader. — Bibliogr. s. 4248–4249, Abstr.
Autorzy (2)
Dane bibliometryczne
| ID BaDAP | 168458 |
|---|---|
| Data dodania do BaDAP | 2026-07-20 |
| Tekst źródłowy | URL |
| Rok publikacji | 2026 |
| Typ publikacji | materiały konferencyjne (aut.) |
| Otwarty dostęp | |
| Creative Commons | |
| Konferencja | IEEE Conference on Computer Vision and Pattern Recognition 2026 |
Abstract
Deep learning is now central to radiology, helping detect changes on X-rays, CTs, and MRIs. However, these systems are highly vulnerable to adversarial attacks - small, crafted perturbations that mislead models while appearing unchanged to humans. Such errors risk missed cancers or false positives. Studies show over 90% attack success on medical scans. Almost 30% of US hospitals use AI in imaging in 2023. Thus, an effective method of detecting such attacks and their directionality is crucial to ensure the credibility and reliability of medical systems based on DNNs. We propose a novel detection framework that leverages subsequent attacks using random noise to identify adversarial perturbations. Our approach uses the analysis of variations in the Sigmoid function to distinguish genuine medical images from adversarially manipulated ones. Specifically, we compare prediction differences between clean and attacked images, as well as between different adversarially altered versions, to improve detection accuracy. We evaluated our method on three popular medical datasets including 'Chest X-Ray Images for Classification', 'Retinal Fundus Multi-disease Image Dataset' and 'Brain Tumor Dataset' under various attack scenarios, including random noise. Our framework achieved up to 99.8% ACC in identifying adversarial directional attacks, significantly outperforming existing defense mechanisms. It consistently identified adversarial samples across varying attack strengths while keeping false positives low, showing strong reliability and potential for clinical use. Furthermore, our proposal highlights its potential for real-world deployment.