Advanced search
Start date
Betweenand


Assessing Vulnerabilities of Deep Learning Explainability in Medical Image Analysis Under Adversarial Settings

Full text
Author(s):
Show less -
de Aguiar, Erikson J. ; Costa, Marcus V. L. ; Traina-, Caetano, Jr. ; Traina, Agora J. M. ; Almeida, JR ; Spiliopoulou, M ; Andrades, JAB ; Placidi, G ; Gonzalez, AR ; Sicilia, R ; Kane, B
Total Authors: 11
Document type: Journal article
Source: 2023 IEEE 36TH INTERNATIONAL SYMPOSIUM ON COMPUTER-BASED MEDICAL SYSTEMS, CBMS; v. N/A, p. 4-pg., 2023-01-01.
Abstract

Deep Learning (DL) is a valuable set of techniques that improve medical decision-making based on imaging exams, such as Chest X-rays (CXR), Computed Tomography (CT), and Optical Coherence Tomography (OCT). However, DL models may be susceptible to adversarial attacks when perturbed (tampered) examples sneak into the data, decreasing the model's confidence. In this paper, we evaluate the vulnerabilities of DL applied to medical images and analyze the effects of attacks on the Gradient-weighted Class Activation Mapping (GRAD-CAM). Our experiments were conducted on two scenarios: (i) CXR images with binary class; (ii) OCT images with multi-class. Vulnerabilities are described by Fooling Rate (FR) and visual analysis of Grad-CAM. We show that the PGD is the most malicious deed for multi-class, reaching an FR of up to 96%, whereas DeepFool is hurtful for binary classes, reaching an FR of up to 93%. Our analysis can be used to understand the adversarial attacks over medical images and their effects on explainability. The developed code is available at GitHub(1). (AU)

FAPESP's process: 16/17078-0 - Mining, indexing and visualizing Big Data in clinical decision support systems (MIVisBD)
Grantee:Agma Juci Machado Traina
Support Opportunities: Research Projects - Thematic Grants
FAPESP's process: 20/07200-9 - Analyzing complex data from COVID-19 to support decision making and prognosis
Grantee:Agma Juci Machado Traina
Support Opportunities: Regular Research Grants
FAPESP's process: 21/08982-3 - Security and privacy in machine learning models to medical images against adversarial attacks
Grantee:Erikson Júlio de Aguiar
Support Opportunities: Scholarships in Brazil - Doctorate