Skip to main content
QUICK REVIEW

[論文レビュー] Now You See It, Now You Dont: Adversarial Vulnerabilities in Computational Pathology

Alex Foote, Amina Asif|arXiv (Cornell University)|Jun 14, 2021
Adversarial Robustness in Machine Learning参考文献 35被引用数 8
ひとこと要約

この論文は、計算病理学分野におけるディープラーニングモデルが、人間には見えないほどの摂動によって予測を信頼性高く反転させられることを示している。AUC > 0.95を達成しているにもかかわらず、最小限のエネルギーでインスタンス固有およびユニバーサルな adversarial perturbations によってモデルがだますことができ、臨床応用における深刻な安全性の懸念を呈している。

ABSTRACT

Deep learning models are routinely employed in computational pathology (CPath) for solving problems of diagnostic and prognostic significance. Typically, the generalization performance of CPath models is analyzed using evaluation protocols such as cross-validation and testing on multi-centric cohorts. However, to ensure that such CPath solutions are robust and safe for use in a clinical setting, a critical analysis of their predictive performance and vulnerability to adversarial attacks is required, which is the focus of this paper. Specifically, we show that a highly accurate model for classification of tumour patches in pathology images (AUC > 0.95) can easily be attacked with minimal perturbations which are imperceptible to lay humans and trained pathologists alike. Our analytical results show that it is possible to generate single-instance white-box attacks on specific input images with high success rate and low perturbation energy. Furthermore, we have also generated a single universal perturbation matrix using the training dataset only which, when added to unseen test images, results in forcing the trained neural network to flip its prediction labels with high confidence at a success rate of > 84%. We systematically analyze the relationship between perturbation energy of an adversarial attack, its impact on morphological constructs of clinical significance, their perceptibility by a trained pathologist and saliency maps obtained using deep learning models. Based on our analysis, we strongly recommend that computational pathology models be critically analyzed using the proposed adversarial validation strategy prior to clinical adoption.

研究の動機と目的

  • 高い診断精度を示すにもかかわらず、最先端の計算病理学モデルが adversarial 攻撃に対してどれほど脆弱であるかを調査すること。
  • adversarial perturbations が一般の人々および熟練した病理医によってどれほど視認可能であるかを評価すること。
  • 摂動エネルギー、組織構造の形態的変化、およびサリエンシー地図の変化との関係を分析すること。
  • 臨床AIモデル向けの adversarial な頑健性評価戦略の開発および検証すること。
  • CPathシステムの臨床的導入の前提条件として adversarial validation を提唱すること。

提案手法

  • 勾配ベースの最適化を用いて、最小限の摂動を生成する白箱攻撃を腫瘍パッチ分類モデルに適用した。
  • 訓練データセット上で1つのユニバーサル摂動行列を学習し、未知のテスト画像へ適用可能とした。
  • 熟練した病理医による知覚的評価を用いて、adversarial 例の視覚的検出可能性を評価した。
  • 臨床的関連性指標を用いて、摂動によって引き起こされた組織構造の形態的変化を分析した。
  • 元の入力と adversarial 入力からのサリエンシー地図を生成・比較し、モデルの注目領域のシフトを検討した。
  • 複数のテスト画像において攻撃の成功率と摂動エネルギー(L2ノルム)を評価した。

実験結果

リサーチクエスチョン

  • RQ1非常に高い精度を示す計算病理学モデルは、人間には見えない adversarial 摂動によって信頼性高くだませるのか?
  • RQ2adversarial 摂動は熟練した病理医によってどの程度検出可能なのか?
  • RQ3adversarial 摂動のエネルギーと組織構造における形態的変化の間にはどのような相関関係があるのか?
  • RQ41つのユニバーサル摂動が多様なテスト画像においてモデルの予測を反転させる成功率はどの程度か?
  • RQ5元の入力と adversarial 入力におけるサリエンシー地図の違いは、モデルの注目領域のシフトを示唆するのか?

主な発見

  • AUC > 0.95を達成する高精度なモデルが、単一インスタンスの白箱摂動によって高い成功率かつ低いエネルギーで攻撃に成功した。
  • ユニバーサル摂動行列は、未知のテスト画像において84%以上の予測反転成功率を達成し、同時に人間には見えないままであった。
  • adversarial 摂動は一般の人々および熟練した病理医の両方にとって見えにくく、視覚的検出性が低いことが示された。
  • 低エネルギー摂動によって組織構造に顕著な形態的変化が引き起こされたが、これは臨床的安全性の懸念を喚起するものであった。
  • サリエンシー地図は、元の入力と adversarial 入力との間で注目領域に顕著なシフトを示し、モデルの推論が信頼できないことを示唆した。
  • 本研究は、交差検証のような標準的な評価プロトコルだけでは、adversarial 攻撃に対する頑健性を保証できないことを示した。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。