2020/09/07 by Michal Byra, Michał Byra, Grzegorz Styczyński +20
Biochemistry, Genetics and Molecular Biology · Computer Science · Engineering · Medicine · Physics and Astronomy · #Adversarial Robustness in Machine Learning #Autopsy Techniques and Outcomes #Bacillus and Francisella bacterial research #Computer Vision and Pattern Recognition (cs.CV) #FOS: Computer and information sciences #FOS: Electrical engineering #FOS: Physical sciences #Image and Video Processing (eess.IV) #Medical Physics (physics.med-ph) #cs.CV #eess.IV #electronic engineering #information engineering #physics.med-ph
paper · pdf · doi:10.48550/arxiv.2009.03364
4 pages, 3 figures
arxiv created 2020/09/07 · openalex publication_date 2020/09/07 · arxiv updated 2020/09/09 · openalex created_date 2022/07/25 · openalex updated_date 2026/07/28
Convolutional neural networks (CNNs) have achieved remarkable success in medical image analysis tasks. In ultrasound (US) imaging, CNNs have been applied to object classification, image reconstruction and tissue characterization. However, CNNs can be vulnerable to adversarial attacks, even small perturbations applied to input data may significantly affect model performance and result in wrong output. In this work, we devise a novel adversarial attack, specific to ultrasound (US) imaging. US images are reconstructed based on radio-frequency signals. Since the appearance of US images depends on the applied image reconstruction method, we explore the possibility of fooling deep learning model by perturbing US B-mode image reconstruction method. We apply zeroth order optimization to find small perturbations of image reconstruction parameters, related to attenuation compensation and amplitude compression, which can result in wrong output. We illustrate our approach using a deep learning model developed for fatty liver disease diagnosis, where the proposed adversarial attack achieved success rate of 48%.