2020/01/27 by Ibrahim Yilmaz, Yilmaz, Ibrahim · 1 citation
Biochemistry, Genetics and Molecular Biology · Computer Science · Medicine · #Adversarial Robustness in Machine Learning #Anomaly Detection Techniques and Applications #Bacillus and Francisella bacterial research #COVID-19 diagnosis using AI #Computer Vision and Pattern Recognition (cs.CV) #FOS: Computer and information sciences #FOS: Electrical engineering #Image and Video Processing (eess.IV) #Machine Learning (cs.LG) #Machine Learning (stat.ML) #electronic engineering #information engineering
paper · pdf · doi:10.48550/arxiv.2001.09610
openalex publication_date 2020/01/27 · openalex created_date 2022/07/26 · openalex updated_date 2026/07/28
Artificial intelligence (AI) has been a topic of major research for many\nyears. Especially, with the emergence of deep neural network (DNN), these\nstudies have been tremendously successful. Today machines are capable of making\nfaster, more accurate decision than human. Thanks to the great development of\nmachine learning (ML) techniques, ML have been used many different fields such\nas education, medicine, malware detection, autonomous car etc. In spite of\nhaving this degree of interest and much successful research, ML models are\nstill vulnerable to adversarial attacks. Attackers can manipulate clean data in\norder to fool the ML classifiers to achieve their desire target. For instance;\na benign sample can be modified as a malicious sample or a malicious one can be\naltered as benign while this modification can not be recognized by human\nobserver. This can lead to many financial losses, or serious injuries, even\ndeaths. The motivation behind this paper is that we emphasize this issue and\nwant to raise awareness. Therefore, the security gap of mammographic image\nclassifier against adversarial attack is demonstrated. We use mamographic\nimages to train our model then evaluate our model performance in terms of\naccuracy. Later on, we poison original dataset and generate adversarial samples\nthat missclassified by the model. We then using structural similarity index\n(SSIM) analyze similarity between clean images and adversarial images. Finally,\nwe show how successful we are to misuse by using different poisoning factors.\n