Robustifying Deep Networks for Medical Image Segmentation

Robustifying Deep Networks for Medical Image Segmentation
复制标题

强化医学图像分割的深度网络

DOI:
10.1007/s10278-021-00507-5
复制
发表时间:
2021
影响因子:
4.4
通讯作者:
McMillan, Alan B.
McMillan, Alan B.
中科院分区:
工程技术2区
文献类型:
--
作者:
Liu, Zheng;Zhang, Jinnian;Jog, Varun;Loh, Po-Ling;McMillan, Alan B.

文献摘要

参考文献

相似文献

这项研究的目的是研究一种常用的卷积神经网络在图像分割中对于几乎不可察觉的对抗性扰动的鲁棒性,并提出新的方法来使这些网络对此类扰动具有更强的鲁棒性。在这项回顾性研究中,研究了低级别和高级别胶质瘤受试者脑肿瘤分割的准确性。两个有代表性的UNET被用来将四个不同的MR序列(T1加权、增强后T1加权、T2加权和T2加权的FLAIR)分割成四个像素化的标记(Gd增强肿瘤、瘤周水肿、坏死性和非强化肿瘤以及背景)。我们开发了基于快速梯度符号方法(FGSM)、迭代FGSM(i-FGSM)和目标迭代FGSM(ti-FGSM)的攻击策略,以产生有效但不可察觉的攻击。此外,我们还探索了通过数据增强来对抗这些对抗性攻击的蒸馏和对抗性训练的有效性。稳健性是通过使用Wilcoxon符号等级测试比较攻击的骰子系数来衡量的。实验结果表明,基于FGSM、i-FGSM和ti-FGSM的攻击能够有效地降低Dice系数中65%的图像分割质量。在攻击防御方面,蒸馏法的表现明显好于对抗性训练方法。然而,与未受干扰的测试图像相比,所有防御方法的表现都更差。因此,有针对性的攻击可能会对分割网络造成不利影响,这些攻击会对现有图像进行视觉上的微小修改(并且可能无法检测到)。随着人们对将深度学习技术应用于医学成像数据的兴趣与日俱增,量化敌对输入(无论是有意还是无意的)的后果变得重要。
The purpose of this study is to investigate the robustness of a commonly used convolutional neural network for image segmentation with respect to nearly unnoticeable adversarial perturbations, and suggest new methods to make these networks more robust to such perturbations. In this retrospective study, the accuracy of brain tumor segmentation was studied in subjects with low- and high-grade gliomas. Two representative UNets were implemented to segment four different MR series (T1-weighted, post-contrast T1-weighted, T2-weighted, and T2-weighted FLAIR) into four pixelwise labels (Gd-enhancing tumor, peritumoral edema, necrotic and non-enhancing tumor, and background). We developed attack strategies based on the fast gradient sign method (FGSM), iterative FGSM (i-FGSM), and targeted iterative FGSM (ti-FGSM) to produce effective but imperceptible attacks. Additionally, we explored the effectiveness of distillation and adversarial training via data augmentation to counteract these adversarial attacks. Robustness was measured by comparing the Dice coefficients for the attacks using Wilcoxon signed-rank tests. The experimental results show that attacks based on FGSM, i-FGSM, and ti-FGSM were effective in reducing the quality of image segmentation by up to 65% in the Dice coefficient. For attack defenses, distillation performed significantly better than adversarial training approaches. However, all defense approaches performed worse compared to unperturbed test images. Therefore, segmentation networks can be adversely affected by targeted attacks that introduce visually minor (and potentially undetectable) modifications to existing images. With an increasing interest in applying deep learning techniques to medical imaging data, it is important to quantify the ramifications of adversarial inputs (either intentional or unintentional).
使用 3D U-Net 高精度提取气管和支气管
DOI: --
发表时间: 2023
期刊:
影响因子: --
作者:
小笠 竜哉;黒田 陸斗;河田 佳樹;鈴木 秀宣;松元 祐司;土田 敬明;楠本 昌彦;仁木 登
通讯作者: 仁木 登
DOI: 10.1016/j.dsp.2017.10.011
发表时间: 2018-02-01
影响因子: 2.9
作者:
Montavon, Gregoire;Samek, Wojciech;Mueller, Klaus-Robert
通讯作者: Mueller, Klaus-Robert
利用深度学习和海运物流大数据预测航运市场状况的研究
DOI: --
发表时间: 2019
期刊:
影响因子: --
作者:
和田 祐次郎;河原 大輝;濱田 邦裕
通讯作者: 濱田 邦裕
DOI: 10.1016/j.carbpol.2014.05.090
发表时间: 2014-11-04
影响因子: 11.2
作者:
Pereira, Andre Luis S.;do Nascirnento, Diego M.;Rosa, Morsyleide de F.
通讯作者: Rosa, Morsyleide de F.
DOI: 10.1016/s1076-6332(03)00671-8
发表时间: 2004-02-01
期刊: ACADEMIC RADIOLOGY
影响因子: 4.8
作者:
Zou, KH;Warfield, SK;Kikinis, R
通讯作者: Kikinis, R