Skip to content
Open access

One-Pixel Attacks Can Improve the Correctness of Prediction

Jul 2026 · Applied Sciences · 0 citations

Abstract

Convolutional neural networks (CNNs) are widely used in medical image classification, yet their robustness to localized perturbations remains limited. This study evaluates one-pixel attacks on VGG16, MobileNetV2, and EfficientNetV2-B0 using brain tumor MRI images resized to 96 × 96 pixels. Each pixel was systematically perturbed across grayscale intensities, and model responses were analyzed in terms of vulnerability, recoverability, and pixel-level sensitivity. The relationship between prediction confidence and influential pixel locations was also examined. Results show that all models remain vulnerable to one-pixel perturbations despite high accuracy. Misclassified samples exhibit more successful attack locations, while correctly classified samples are more robust. Higher-intensity perturbations more often restore correct predictions in misclassified cases. A monotonic relationship is observed between prediction confidence and pixel sensitivity, where lower confidence corresponds to more influential pixels. Recovery points show spatially concentrated patterns. Overall, pixel-level sensitivity is more strongly associated with prediction correctness and local perturbations than with confidence. These findings are consistent across architectures and suggest that one-pixel analysis is useful for assessing CNN robustness in medical imaging.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.