Robustifying Deep Networks for Medical Image Segmentation
Robustifying Deep Networks for Medical Image Segmentation
复制标题
强化医学图像分割的深度网络
DOI:
10.1007/s10278-021-00507-5
复制
发表时间:
2021
影响因子:
4.4
通讯作者:
McMillan, Alan B.
中科院分区:
文献类型:
--
作者:
Liu, Zheng;Zhang, Jinnian;Jog, Varun;Loh, Po-Ling;McMillan, Alan B.
The purpose of this study is to investigate the robustness of a commonly used convolutional neural network for image segmentation with respect to nearly unnoticeable adversarial perturbations, and suggest new methods to make these networks more robust to such perturbations. In this retrospective study, the accuracy of brain tumor segmentation was studied in subjects with low- and high-grade gliomas. Two representative UNets were implemented to segment four different MR series (T1-weighted, post-contrast T1-weighted, T2-weighted, and T2-weighted FLAIR) into four pixelwise labels (Gd-enhancing tumor, peritumoral edema, necrotic and non-enhancing tumor, and background). We developed attack strategies based on the fast gradient sign method (FGSM), iterative FGSM (i-FGSM), and targeted iterative FGSM (ti-FGSM) to produce effective but imperceptible attacks. Additionally, we explored the effectiveness of distillation and adversarial training via data augmentation to counteract these adversarial attacks. Robustness was measured by comparing the Dice coefficients for the attacks using Wilcoxon signed-rank tests. The experimental results show that attacks based on FGSM, i-FGSM, and ti-FGSM were effective in reducing the quality of image segmentation by up to 65% in the Dice coefficient. For attack defenses, distillation performed significantly better than adversarial training approaches. However, all defense approaches performed worse compared to unperturbed test images. Therefore, segmentation networks can be adversely affected by targeted attacks that introduce visually minor (and potentially undetectable) modifications to existing images. With an increasing interest in applying deep learning techniques to medical imaging data, it is important to quantify the ramifications of adversarial inputs (either intentional or unintentional).
登录
查看更多内容
DOI:
--
发表时间:
2023
期刊:
影响因子:
--
作者:
小笠 竜哉;黒田 陸斗;河田 佳樹;鈴木 秀宣;松元 祐司;土田 敬明;楠本 昌彦;仁木 登
通讯作者:
仁木 登
影响因子:
2.9
作者:
Montavon, Gregoire;Samek, Wojciech;Mueller, Klaus-Robert
通讯作者:
Mueller, Klaus-Robert
DOI:
--
发表时间:
2019
期刊:
影响因子:
--
作者:
和田 祐次郎;河原 大輝;濱田 邦裕
通讯作者:
濱田 邦裕
影响因子:
11.2
作者:
Pereira, Andre Luis S.;do Nascirnento, Diego M.;Rosa, Morsyleide de F.
通讯作者:
Rosa, Morsyleide de F.
影响因子:
4.8
作者:
Zou, KH;Warfield, SK;Kikinis, R
通讯作者:
Kikinis, R