Skip to main navigation Skip to search Skip to main content

Adversarial robustness enhancement in deep learning-based breast cancer classification: A multi-faceted approach to poisoning and Evasion attack mitigation

  • Lourdu Mahimai Doss P
  • , Muthumanickam Gunasekaran
  • , Jungeun Kim
  • , Seifedine Kadry
  • Saveetha Institute of Medical and Technical Sciences (Deemed to be University)
  • Inha University
  • Noroff University College
  • Lebanese American University

Research output: Contribution to journalArticlepeer-review

8 Scopus citations

Abstract

Deep learning models used in medical image classification continue to be vulnerable to adversarial attacks, particularly in the case of Invasive Ductal Carcinoma (IDC). The proposed attacks will negatively impact the integrity and reliability of the model. This work optimizes Convolutional Neural Networks (CNN) used for IDC classification. A competitive CNN designed and trained on the IDC dataset using Stochastic Gradient Descent with Momentum (SGD) as the optimizer achieved a training accuracy of 99 % and a testing accuracy of 80 %. The paper evaluates the extent to which this model is susceptible to adversarial manipulation, notably Poison and Evasion attacks. The research reveals that poisonous attacks, notably those of the Layer-wise Model Distortion (LMD) framework with feature-space poison injection, resulted in the model achieving an accuracy of 66 %. Evasion attacks using the Fast Gradient Sign Method (FGSM) under the LMD framework led to an accuracy of 92 %. To bridge the discussed gaps, new defense techniques have been proposed and tested using Layer-wise Robustness Enhancement (LRF). Defense techniques involved dynamic layer-wise weighting, leading overall accuracies against poison attacks to surge to 76 %, and adaptive denoising to lead overall accuracies against evasion attacks to 79 %. This study discussed the seminal issue of adversarial manipulation in medical picture classification and how some defenses are justified in the LRF framework to substantially improve the model's resiliency, integrity, and trust.

Original languageEnglish
Pages (from-to)65-82
Number of pages18
JournalAlexandria Engineering Journal
Volume115
DOIs
StatePublished - Mar 2025
Externally publishedYes

UN SDGs

This output contributes to the following UN Sustainable Development Goals (SDGs)

  1. SDG 3 - Good Health and Well-being
    SDG 3 Good Health and Well-being

Keywords

  • Adaptive Denoising Layers
  • Adversarial robustness
  • Dynamic Layer-wise Weighting
  • Evasion attack
  • Feature-space poison injection
  • Poisoning attack
  • Stochastic Gradient Descent with Momentum

Fingerprint

Dive into the research topics of 'Adversarial robustness enhancement in deep learning-based breast cancer classification: A multi-faceted approach to poisoning and Evasion attack mitigation'. Together they form a unique fingerprint.

Cite this