Skip to content

Securing Medical AI: Adversarial Attack Detection and Mitigation in CAD Systems

Oct 2026 · IEEE Transactions on Emerging Topics in Computational Intelligence · Vol 10, pp. 3836-3848 · 0 citations · 49 references

Abstract

Frequency-constrained adversarial attacks introduce imperceptible, high-frequency distortions that undermine the reliability and safety of AI-assisted medical diagnostics, posing a serious challenge to trust and resilience in socially-interactive, human-AI healthcare systems. To address this, we introduce Sentinel, a pioneering framework that detects, classifies, and mitigates adversarial attacks in medical image analysis without requiring training or model specificity. Sentinel integrates a lightweight detection module that uses a confidence scorer to analyze predictions from multiple low-rank approximations of the input image, enabling precise classification of attacks as either gradient-based or frequency-constrained. Uniquely, Sentinel includes a recovery module specifically designed for frequency-constrained attacks, employing adaptive Robust Principal Component Analysis-based denoising to suppress perturbations concentrated in smaller singular values while preserving essential image structure. This allows for effective image reconstruction, an area overlooked by existing methods. Evaluated across four diverse medical imaging datasets, Sentinel demonstrates consistently high detection accuracy, classification performance, and adversarial recovery without the need for model retraining or GPU support, making it a highly practical and scalable solution for integration into clinical AI systems. Additional explainability analyses confirm the reliability and interpretability of Sentinel's predictions, establishing it as a significant advancement in adversarial defense.

View source

Similar papers

Sep 2026

Seeing Through Threats: Adversarial Detection Through Explainability (ADEx)

Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependen...

Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al. · 0 citations
Conference Aug 2026

Advances in Detecting and Mitigation Adversarial Manipulations in Medical Imaging: A Review

Medical Image Analysis has seen remarkable improvements with Deep Learning (DL), which have helped in refining the accuracy of disease detection, diagnosis, and clinical decision support. But these models are still very vulnerable to Adversarial Attacks, in which subtle yet carefully engineered perturbations can lead t...

Drashti Deveshbhai Patel, Jaimeel Shah, A. Kushwaha · 0 citations
Open access Sep 2026

PatchGuard-Freq: Zero-Overhead Adversarial Patch Defense via Frequency Detection and Data-Driven Robustness

This work characterizes the complementary relationship between reconstruction-based and robustness-based paradigms in the accuracy–efficiency design space under the evaluated conditions: the former suits compute-unconstrained scenarios while the latter serves latency-constrained deployments.

De-Jie Luan, Cheng-Hua Li, Chun-Jie Zhang et al. · 0 citations
Open access Aug 2026

A Comprehensive AI Security Pipeline: Drift Detection, Adversarial Robustness and Automated ML Testing

The wide-scale uptake of machine learning applications in safety-sensitive applications renders modern AI deployments prone to adversarial attacks, statistical distribution changes, and various governance reliability issues. Current AI security methodologies generally handle the discussed issues separately, making the...

Siddharth Kumar, Siddhanth Harish Bist · 0 citations

Related blog posts

Microsoft Research Blog Oct 7, 2026

Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses

Training AI agents with reinforcement learning can be challenging because their tools, context, and decision-making are managed by complex frameworks. Agent Lightning connects existing agents to RL training, making it easier to improve them without rebuilding them. The post Agent Lightning v1.0: A 3,500-Line Lightweight Agentic RL Framework for Training Agents with Real Harnesses appeared first on Microsoft Research.

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.