Injecting and removing suspicious features in breast imaging with CycleGAN: A pilot study of automated adversarial attacks using neural networks on small images

Injecting and removing suspicious features in breast imaging with CycleGAN: A pilot study of automated adversarial attacks using neural networks on small images
复制标题

DOI:
10.1016/j.ejrad.2019.108649
复制
发表时间:
2019-11-01
影响因子:
3.3
通讯作者:
Konukoglu, Ender
Konukoglu, Ender
中科院分区:
医学3区
文献类型:
--
作者:
Becker, Anton S.;Jendele, Lukas;Konukoglu, Ender

文献摘要

被引文献

相似文献

目的:为了训练一个CycleGAN的缩小版本的乳房X线摄影数据,人工注入或删除可疑的功能,并确定这些AI介导的攻击是否可以检测到radiologist.Material和方法:从两个公开的数据集,BCDR和INbreast,我们选择了680图像与不病变作为训练数据。内部数据集(n = 302例癌症,n = 590例对照)用作测试数据。我们运行了两个实验(256 x 256 px和512 x 408 px),并将训练好的模型应用于测试数据。三名放射科医生阅读一组图像(修改后的和原始的),并在1到5的量表上对可疑病变的存在和图像被操纵的可能性进行评级。使用曲线下面积(AUC)通过多个读取器多病例受试者操作特征(MRMC-ROC)分析来评估读数。结果:在较低分辨率下,总体性能不受CycleGAN修改的影响(AUC 0.70 vs. 0.76,p = 0.67)。然而,一名放射科医生表现出较低的癌症检测(0.85 vs 0.63,p = 0.06)。放射科医师无法区分原始图像和修改后的图像(0.55,p = 0.45)。在更高的分辨率下,所有放射科医生在修改后的图像中显示出明显更低的癌症检出率(0.80 vs. 0.37,p < 0.001),然而,由于伪影的可见性更好,他们能够检测到修改后的图像(0.94,p < 0.0001)。我们的概念验证研究表明,CycleGAN可以隐式地学习可疑特征,并在现有图像中人工注入或删除它们。该方法的适用性目前受到小图像尺寸和伪影引入的限制。
Purpose: To train a CycleGAN on downscaled versions of mammographic data to artificially inject or remove suspicious features, and to determine whether these AI-mediated attacks can be detected by radiologists.Material and Methods: From two publicly available datasets, BCDR and INbreast, we selected 680 images with and without lesions as training data. An internal dataset (n = 302 cancers, n = 590 controls) served as test data. We ran two experiments (256 x 256 px and 512 x 408 px) and applied the trained model to the test data. Three radiologists read a set of images (modified and originals) and rated the presence of suspicious lesions on a scale from 1 to 5 and the likelihood of the image being manipulated. The readout was evaluated by multiple reader multiple case receiver operating characteristics (MRMC-ROC) analysis using the area under the curve (AUC).Results: At the lower resolution, the overall performance was not affected by the CycleGAN modifications (AUC 0.70 vs. 0.76, p = 0.67). However, one radiologist exhibited lower detection of cancer (0.85 vs 0.63, p = 0.06). The radiologists could not discriminate between original and modified images (0.55, p = 0.45). At the higher resolution, all radiologists showed significantly lower detection rate of cancer in the modified images (0.80 vs. 0.37, p < 0.001), however, they were able to detect modified images due to better visibility of artifacts (0.94, p < 0.0001).Conclusion: Our proof-of-concept study shows that CycleGAN can implicitly learn suspicious features and artificially inject or remove them in existing images. The applicability of the method is currently limited by the small image size and introduction of artifacts.