Improving Robustness of Deep-Learning-Based Image Reconstruction

Improving Robustness of Deep-Learning-Based Image Reconstruction
复制标题

DOI:
--
复制
发表时间:
2020-02
期刊:
--
影响因子:
--
通讯作者:
Ankit Raj;Y. Bresler;Bo Li
Ankit Raj;Y. Bresler;Bo Li
中科院分区:
其他
文献类型:
--
作者:
Ankit Raj;Y. Bresler;Bo Li

文献摘要

被引文献

相似文献

针对不同应用的基于深度学习的方法已被证明容易受到对抗性示例的影响。这些例子使得在安全关键任务中部署此类模型成为问题。使用深度神经网络作为逆问题求解器已经为包括CT和MRI在内的医学成像带来了很多兴奋,但最近这些任务也出现了类似的漏洞。我们表明,这样的逆问题求解器,应该分析和研究的效果,在测量空间的对手,而不是在以前的工作中的信号空间。在本文中,我们建议修改端到端基于深度学习的逆问题求解器的训练策略,以提高鲁棒性。我们引入了一个辅助网络来生成对抗性的例子,它被用于最小-最大公式来构建鲁棒的图像重建网络。从理论上讲,我们证明了线性重建方案的最小-最大公式导致奇异值滤波器正则化解决方案,它抑制了由于测量矩阵中的病态而发生的对抗性示例的影响。我们发现,使用所提出的最小-最大学习方案的线性网络确实收敛到相同的解决方案。此外,对于使用深度网络的非线性压缩感知(CS)重建,我们使用所提出的方法比其他方法在鲁棒性方面显着提高。我们通过在两个不同数据集上进行CS实验来补充理论,并评估增加扰动对训练网络的影响。我们发现病态和良好条件的测量矩阵的行为是定性不同的。
Deep-learning-based methods for different applications have been shown vulnerable to adversarial examples. These examples make deployment of such models in safety-critical tasks questionable. Use of deep neural networks as inverse problem solvers has generated much excitement for medical imaging including CT and MRI, but recently a similar vulnerability has also been demonstrated for these tasks. We show that for such inverse problem solvers, one should analyze and study the effect of adversaries in the measurement-space, instead of the signal-space as in previous work. In this paper, we propose to modify the training strategy of end-to-end deep-learning-based inverse problem solvers to improve robustness. We introduce an auxiliary network to generate adversarial examples, which is used in a min-max formulation to build robust image reconstruction networks. Theoretically, we show for a linear reconstruction scheme the min-max formulation results in a singular-value(s) filter regularized solution, which suppresses the effect of adversarial examples occurring because of ill-conditioning in the measurement matrix. We find that a linear network using the proposed min-max learning scheme indeed converges to the same solution. In addition, for non-linear Compressed Sensing (CS) reconstruction using deep networks, we show significant improvement in robustness using the proposed approach over other methods. We complement the theory by experiments for CS on two different datasets and evaluate the effect of increasing perturbations on trained networks. We find the behavior for ill-conditioned and well-conditioned measurement matrices to be qualitatively different.