Reliable skin cancer diagnosis models play an essential role in early screening and medical intervention. Prevailing computer-aided skin cancer classification systems employ deep learning approaches. However, recent studies reveal their extreme vulnerability to adversarial attacks -- often imperceptible perturbations to significantly reduce the performances of skin cancer diagnosis models. To mitigate these threats, this work presents a simple, effective, and resource-efficient defense framework by reverse engineering adversarial perturbations in skin cancer images. Specifically, a multiscale image pyramid is first established to better preserve discriminative structures in the medical imaging domain. To neutralize adversarial effects, skin images at different scales are then progressively diffused by injecting isotropic Gaussian noises to move the adversarial examples to the clean image manifold. Crucially, to further reverse adversarial noises and suppress redundant injected noises, a novel multiscale denoising mechanism is carefully designed that aggregates image information from neighboring scales. We evaluated the defensive effectiveness of our method on ISIC 2019, a largest skin cancer multiclass classification dataset. Experimental results demonstrate that the proposed method can successfully reverse adversarial perturbations from different attacks and significantly outperform some state-of-the-art methods in defending skin cancer diagnosis models.
翻译:可靠的皮肤癌诊断模型在早期筛查和医疗干预中发挥着不可或缺的作用。常用的计算机辅助皮肤癌分类系统采用深层学习方法。然而,最近的研究表明,它们极易受到对抗性攻击的极端脆弱性 -- -- 往往无法察觉的扰动,以大幅降低皮肤癌诊断模型的性能。为减轻这些威胁,这项工作提供了一个简单、有效和资源节约的防御框架,在皮肤癌图像中反向工程对抗性扰动。具体地说,为了更好地保护医疗成像领域的歧视性结构,首先建立了一个多尺度图像金字塔。为了消除对抗性影响,不同尺度的皮肤图像随后通过注射异位高山噪音逐渐扩散,以便将对抗性攻击性例子移到清洁的图象柱上。至关重要的是,为了进一步扭转对抗性噪音和抑制多余的注入性噪音,正在仔细设计一种新型的多尺度消音机制,将相邻的图像信息汇总起来。我们评估了我们关于ISIC 2019的方法的防御有效性,这是最大的皮肤癌多级分类数据集。实验结果表明,拟议的方法可以成功地扭转不同皮肤诊断模型的对抗性透视像模型。