The study concluded that adversarial resilience is largely determined by the interaction between model architecture and defense strategy, highlighting the need for architecture-specific defense selection when developing secure medical image classification systems.
Abstract
This study aims to systematically evaluate the adversarial robustness of Convolutional Neural Network (CNN), VGG19, and Vision Transformer (ViT) architectures for chest X-ray classification. Specifically,this study aims to determine the relative influence of model architectures and defense strategies under identical experimental conditions The research method: All three architectures were evaluated using a chest X-ray dataset under white-box attacks using the Fast Gradient Sign Method (FGSM) and the Iterative Fast Gradient Sign Method (IFGSM), with perturbation levels ranging from ε = 0.00 to 0.30. Five defense strategies-Adversarial Training, Adversarial Distillation, TRADES, MART, and Adversarial Weight Perturbation (AWP)-were compared to a baseline without defenses within a unified experimental framework. Differences between defense methods were assessed using the Friedman test. The results showed that without defenses, all models experienced substantial performance degradation, with IFGSM causing a more severe degradation than FGSM. Under FGSM attacks, VGG19 demonstrated the most consistent resilience across defense strategies. Under IFGSM attacks, ViT combined with Adversarial Training achieved the strongest resilience. Defense effectiveness varied across architectures, and no single defense consistently performed best. Friedman’s test identified significant differences between defense methods for FGSM and IFGSM attacks across all architectures (p < 0.001). The study concluded that adversarial resilience is largely determined by the interaction between model architecture and defense strategy. Defense selection has a greater impact on resilience than architecture complexity alone, highlighting the need for architecture-specific defense selection when developing secure medical image classification systems.
Among the evaluated models, CNNs exhibit the highest baseline robustness, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance, whereas DNNs and RNNs rely more heavily on defense mechanisms to maintain performance.
Surekha M., A. K. Sagar, Vineeta Khemchandani· International Journal of Int...· 0 citations
This paper advocates for a forward-thinking approach that balances technical sophistication with human-centric principles, ensuring that adversarial deep learning evolves into a discipline not just of technical defense, but also of trust, transparency, and accountability.
Maisam Abbas, Ran-Zan Wang· IEEE Open Journal of the Com...· 0 citations
The research methodology involved a systematic literature review using the Scopus database, adhering to Preferred Reporting Items for Systematic Reviews and Meta-Analyses guidelines, and focusing on recent advancements in attack and defence techniques.
A method to analyze ANNs designed for image classification from an adversarial robustness perspective and implemented an ablation and fine-tuning strategy that successfully boosted the robustness of the ANNs against a variant of the Auto-PGD attack under different threat models.
Empirical support is provided for the utility of structure-aware perturbation refinement in improving black-box adversarial transferability across heterogeneous visual architectures.
Qi-Rui Lu, Liansong Zong, Fu-Ran Liu et al.· Neural Networks· 0 citations
GPU undervolting is a readily deployable hardware-level defense requiring no algorithmic change, and opens a promising direction in which robustness and energy efficiency move together.
Behnam Omidi, Ahmad Tahmasivand, Husam Alsyouri et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.