יובל אלוביץ

אקדמי בכיר

The Security of Deep Learning Defenses in Medical Imaging

Moshe Levy, Guy Amit, Yuval Elovici,Yisroel Mirsky

Deep learning has shown great promise in the medical image analysis domain. Medical professionals and healthcare providers have begun to adopt this technology to accelerate and enhance their work. These systems use deep neural networks (DNNs) which are vulnerable to adversarial samples: images with imperceivable changes that can alter the model's prediction. Prior research has proposed defenses aimed at making DNNs more robust or detecting the adversarial samples before they can do any harm. However, none of the studies considered an informed attacker capable of adapting the attack to the defense mechanism. In this qualitative study, we show that an informed attacker can evade five advanced defenses, successfully fooling the victim deep learning model and rendering the defense useless. We also propose two alternative means of securing healthcare DNNs from such attacks: (1) hardening the system's security, and (2) using digital signatures.

שפת פרסום אנגלית
דפים 37-44
סטטוס פרסום פורסם - 21.11.2024

Keywords

adaptive adversarial attacks
deep learning

ASJC Scopus subject areas

Safety, Risk, Reliability and Quality
Computer Networks and Communications
General Medicine
גישה למסמך
10.1145/3689942.3694746
קבצים וקישורים אחרים
Link to publication in Scopus