Your browser doesn't support javascript.
loading
Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition.
Lal, Sheeba; Rehman, Saeed Ur; Shah, Jamal Hussain; Meraj, Talha; Rauf, Hafiz Tayyab; Damasevicius, Robertas; Mohammed, Mazin Abed; Abdulkareem, Karrar Hameed.
Afiliação
  • Lal S; Department of Computer Science, COMSATS University Islamabad, Wah Campus, Wah Cantt 47040, Pakistan.
  • Rehman SU; Department of Computer Science, COMSATS University Islamabad, Wah Campus, Wah Cantt 47040, Pakistan.
  • Shah JH; Department of Computer Science, COMSATS University Islamabad, Wah Campus, Wah Cantt 47040, Pakistan.
  • Meraj T; Department of Computer Science, COMSATS University Islamabad, Wah Campus, Wah Cantt 47040, Pakistan.
  • Rauf HT; Department of Computer Science, Faculty of Engineering & Informatics, University of Bradford, Bradford BD7 1DP, UK.
  • Damasevicius R; Faculty of Applied Mathematics, Silesian University of Technology, 44-100 Gliwice, Poland.
  • Mohammed MA; College of Computer Science and Information Technology, University of Anbar, Anbar 31001, Iraq.
  • Abdulkareem KH; College of Agriculture, Al-Muthanna University, Samawah 66001, Iraq.
Sensors (Basel) ; 21(11)2021 Jun 07.
Article em En | MEDLINE | ID: mdl-34200216
Due to the rapid growth in artificial intelligence (AI) and deep learning (DL) approaches, the security and robustness of the deployed algorithms need to be guaranteed. The security susceptibility of the DL algorithms to adversarial examples has been widely acknowledged. The artificially created examples will lead to different instances negatively identified by the DL models that are humanly considered benign. Practical application in actual physical scenarios with adversarial threats shows their features. Thus, adversarial attacks and defense, including machine learning and its reliability, have drawn growing interest and, in recent years, has been a hot topic of research. We introduce a framework that provides a defensive model against the adversarial speckle-noise attack, the adversarial training, and a feature fusion strategy, which preserves the classification with correct labelling. We evaluate and analyze the adversarial attacks and defenses on the retinal fundus images for the Diabetic Retinopathy recognition problem, which is considered a state-of-the-art endeavor. Results obtained on the retinal fundus images, which are prone to adversarial attacks, are 99% accurate and prove that the proposed defensive model is robust.
Assuntos
Palavras-chave

Texto completo: 1 Base de dados: MEDLINE Assunto principal: Diabetes Mellitus / Retinopatia Diabética Idioma: En Ano de publicação: 2021 Tipo de documento: Article

Texto completo: 1 Base de dados: MEDLINE Assunto principal: Diabetes Mellitus / Retinopatia Diabética Idioma: En Ano de publicação: 2021 Tipo de documento: Article