Scholarship 21/08982-3 - Aprendizado computacional, Aprendizagem profunda - BV FAPESP
Advanced search
Start date
Betweenand

Security and privacy in machine learning models to medical images against adversarial attacks

Grant number: 21/08982-3
Support Opportunities:Scholarships in Brazil - Doctorate
Start date: March 01, 2022
End date: February 28, 2027
Field of knowledge:Physical Sciences and Mathematics - Computer Science - Computer Systems
Principal Investigator:Agma Juci Machado Traina
Grantee:Erikson Júlio de Aguiar
Host Institution: Instituto de Ciências Matemáticas e de Computação (ICMC). Universidade de São Paulo (USP). São Carlos , SP, Brazil
Associated scholarship(s):23/14759-0 - Privacy-preserving and backdoors defending: towards federated learning in medical settings, BE.EP.DR

Abstract

With the advent of big data, data is being produced and generated on a large scale, used by Machine Learning (ML) models to generate new knowledge. Several areas have benefited from big data and ML, one of them being healthcare, which can employ complex data such as images to assist medical experts in decision making. While these concepts are valuable for healthcare, they can lead to issues regarding patient privacy and security. Information leaks in healthcare systems frequently. For example, in 2020, data of 200,000 patients from public health systems in Brazil was exposed. The ML models employed in healthcare are susceptible to attacks that poison the input data, the model itself and cause problems in the test data. In addition, they can present both known and unknown backdoors. The area of study that proposes defense and attack strategies against ML models is adversarial machine learning, which aims to reduce the model's reliability and cause the model to misclassify the data. Therefore, this project aims to devise a framework consisting of defense, vulnerability exploitation, and attack models to understand and combat security and privacy violations in pattern recognition models in medical images. Medical images are used as input to ML models to recognize patterns and support medical decision-making. However, these images, such as the models that classify them, can suffer attacks to invalidate their robustness or compromise the patient's privacy. In this project, we hope to: (I) develop defensive algorithms against adversarial examples; (II) devise methods to preserve patient privacy; (III) exploit new vulnerabilities and backdoors that ML models may present; (IV) propose attack strategies and their respective defenses, to communicate to other researchers the possible paths an attacker may follow. (AU)

News published in Agência FAPESP Newsletter about the scholarship:
More itemsLess items
Articles published in other media outlets ( ):
More itemsLess items
VEICULO: TITULO (DATA)
VEICULO: TITULO (DATA)

Scientific publications (5)
(References retrieved automatically from Web of Science and SciELO through information on FAPESP grants and their corresponding numbers as mentioned in the publications by the authors)
COSTA, MARCUS V. L.; DE AGUIAR, ERIKSON J.; RODRIGUES, LUCAS S.; RAMOS, JONATHAN S.; TRAINA, CAETANO, JR.; TRAINA, AGMA J. M.; ALMEIDA, JR; SPILIOPOULOU, M; ANDRADES, JAB; PLACIDI, G; et al. A Deep Learning-based Radiomics Approach for COVID-19 Detection from CXR Images using Ensemble Learning Model. 2023 IEEE 36TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS, CBMS, v. N/A, p. 6-pg., . (16/17078-0, 20/07200-9, 21/08982-3)
ELEUTERIO, IGOR ALBERTE R.; DE OLIVEIRA, WILLIAN D.; TEIXEIRA, LARISSA R.; VESPA, THIAGO G.; SILVA, WILLIAM Z.; TRAINA, AGMA JUCI M.; TRAINA JR, CAETANO. Cosim-Gres: Towards Similarity Queries Optimization Inside RDBMS. SOFTWARE-PRACTICE & EXPERIENCE, v. N/A, p. 15-pg., . (21/08982-3, 20/07200-9, 16/17078-0)
DE AGUIAR, ERIKSON J.; TRAINA, CAETANO, JR.; TRAINA, AGMA J. M.. RADAR-MIX: How to Uncover Adversarial Attacks in Medical Image Analysis through Explainability. 2024 IEEE 37TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS, CBMS 2024, v. N/A, p. 6-pg., . (16/17078-0, 21/08982-3, 20/07200-9, 23/14759-0)
RAMOS, JONATHAN S.; DE AGUIAR, ERIKSON J.; BELIZARIO, IVAR, V; COSTA, MARCUS V. L.; MACIEL, JAMILLY G.; CAZZOLATO, MIRELA T.; TRAINA, CAETANO, JR.; NOGUEIRA-BARBOSA, MARCELLO H.; TRAINA, AGMA J. M.; SHEN, L; et al. Analysis of vertebrae without fracture on spine MRI to assess bone fragility: A Comparison of Traditional Machine Learning and Deep Learning. 2022 IEEE 35TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS (CBMS), v. N/A, p. 6-pg., . (21/02412-0, 20/11258-2, 16/17078-0, 21/11403-5, 21/00360-3, 21/08982-3, 18/04266-9)
DE AGUIAR, ERIKSON J.; COSTA, MARCUS V. L.; TRAINA-, CAETANO, JR.; TRAINA, AGORA J. M.; ALMEIDA, JR; SPILIOPOULOU, M; ANDRADES, JAB; PLACIDI, G; GONZALEZ, AR; SICILIA, R; et al. Assessing Vulnerabilities of Deep Learning Explainability in Medical Image Analysis Under Adversarial Settings. 2023 IEEE 36TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS, CBMS, v. N/A, p. 4-pg., . (16/17078-0, 20/07200-9, 21/08982-3)