Backdoor Attacks to Deep Neural Network-Based System for COVID-19 Detection from Chest X-ray Images

Backdoor Attacks to Deep Neural Network-Based System for COVID-19 Detection from Chest X-ray Images
复制标题

DOI:
10.3390/app11209556
复制
发表时间:
2021-10
期刊:
影响因子:
--
通讯作者:
Yuki Matsuo;Kazuhiro Takemoto
Yuki Matsuo;Kazuhiro Takemoto
中科院分区:
--
文献类型:
--
作者:
Yuki Matsuo;Kazuhiro Takemoto

文献摘要

被引文献

相似文献

用于医学成像的开源深度神经网络(DNN)在紧急情况下非常重要,例如在2019年新型冠状病毒病(COVID-19)大流行期间,因为它们加速了基于DNN的高性能系统的开发。然而,在开源开发过程中,对抗性攻击是不可忽视的。由于DNN被用作计算机辅助系统,用于从X射线图像中筛查COVID-19,因此我们研究了COVID-Net模型的漏洞,这是一种代表性的开源DNN,用于从胸部X射线图像中检测COVID-19,以修改DNN模型并在添加特定触发输入时导致其错误分类的后门攻击。结果表明,非目标攻击(DNN将输入分类为不正确的标签)和目标攻击(DNN将输入分类为特定目标类别)的后门可以使用小触发器和小部分训练数据在COVID-Net模型中建立。此外,后门对从后门COVID-Net模型微调的模型有效,尽管非目标攻击的性能有限。这表明后门模型可以通过微调传播(从而成为重大的安全威胁)。研究结果表明,需要重视DNN在COVID-19检测中的开源开发和实际应用。
Open-source deep neural networks (DNNs) for medical imaging are significant in emergent situations, such as during the pandemic of the 2019 novel coronavirus disease (COVID-19), since they accelerate the development of high-performance DNN-based systems. However, adversarial attacks are not negligible during open-source development. Since DNNs are used as computer-aided systems for COVID-19 screening from radiography images, we investigated the vulnerability of the COVID-Net model, a representative open-source DNN for COVID-19 detection from chest X-ray images to backdoor attacks that modify DNN models and cause their misclassification when a specific trigger input is added. The results showed that backdoors for both non-targeted attacks, for which DNNs classify inputs into incorrect labels, and targeted attacks, for which DNNs classify inputs into a specific target class, could be established in the COVID-Net model using a small trigger and small fraction of training data. Moreover, the backdoors were effective for models fine-tuned from the backdoored COVID-Net models, although the performance of non-targeted attacks was limited. This indicated that backdoored models could be spread via fine-tuning (thereby becoming a significant security threat). The findings showed that emphasis is required on open-source development and practical applications of DNNs for COVID-19 detection.