Adversarial attacks and adversarial robustness in computational pathology
Ghaffari Laleh, N.; Truhn, D.; Veldhuizen, G. P.; Han, T.; van Treeck, M.; Buelow, R. D.; Langer, R.; Dislich, B.; Boor, P.; Schulz, V.; Kather, J. N.
Show abstract
Artificial Intelligence (AI) can support diagnostic workflows in oncology by aiding diagnosis and providing biomarkers. AI applications are therefore expected to evolve from academic prototypes to commercial products in the coming years. However, AI applications are vulnerable to adversarial attacks, such as malicious interference with test data aiming to cause misclassifications. Therefore, it is essential for the use of AI-based diagnostic devices to secure them against such attacks before widespread use. Unfortunately, no resistant systems exist in computational pathology so far. To address this problem, we investigate the susceptibility of convolutional neural networks (CNNs) to multiple types of white- and black-box attacks. We demonstrate that both attacks can easily confuse CNNs in clinically relevant pathology tasks and impair classification performance. Classical adversarially robust training and dual batch normalization (DBN) are possible mitigation strategies but require precise knowledge of the type of attack used in the inference. We demonstrate that vision transformers (ViTs) perform equally well compared to CNNs at baseline and are orders of magnitude more robust to different types of white-box and black-box attacks. At a mechanistic level, we show that this is associated with a more robust latent representation of clinically relevant categories in ViTs compared to CNNs. Our results are in line with previous theoretical studies. We show that ViTs are robust learners in computational pathology. This implies that large-scale rollout of AI models in computational pathology should rely on ViTs rather than CNN-based classifiers to provide inherent protection against adversaries.
Matching journals
The top 5 journals account for 50% of the predicted probability mass.
Similar papers in this journal
- Deep transfer learning for reducing health care disparities arising from biomedical data inequality 95%
- STAIG: Spatial Transcriptomics Analysis via Image-Aided Graph Contrastive Learning for Domain Exploration and Alignment-Free Integration 94%
- Generative AI Enables Medical Image Segmentation in Ultra Low-Data Regimes 94%
Similar papers in this journal
Similar papers in this journal
- Generalizing AI-driven Assessment of Immunohistochemistry across Immunostains and Cancer Types: A Universal Immunohistochemistry Analyzer 96%
- A Deep Learning Model for Molecular Label Transfer that Enables Cancer Cell Identification from Histopathology Images 95%
- Explainable, federated deep learning model predicts disease progression risk of cutaneous squamous cell carcinoma 95%
Similar papers in this journal
- Unraveling the complexity of rat object vision requires a full convolutional network - and beyond 94%
- Obtaining Spatially Resolved Tumor Purity Maps Using Deep Multiple Instance Learning In A Pan-cancer Study 94%
- Privacy-Preserving Federated Neural Network Learning for Disease-Associated Cell Classification 94%
"Similar papers" are the closest papers from that journal in the model's embedding space. They show what the match is built on, but the ranking comes mostly from a classifier over the whole training set, not from these examples alone.