{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,21]],"date-time":"2025-09-21T10:26:09Z","timestamp":1758450369626,"version":"3.44.0"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783032049261"},{"type":"electronic","value":"9783032049278"}],"license":[{"start":{"date-parts":[[2025,9,21]],"date-time":"2025-09-21T00:00:00Z","timestamp":1758412800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,21]],"date-time":"2025-09-21T00:00:00Z","timestamp":1758412800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-04927-8_23","type":"book-chapter","created":{"date-parts":[[2025,9,20]],"date-time":"2025-09-20T17:09:00Z","timestamp":1758388140000},"page":"239-249","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Hierarchical Self-supervised Adversarial Training for\u00a0Robust Vision Models in\u00a0Histopathology"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6197-3840","authenticated-orcid":false,"given":"Hashmat Shadab","family":"Malik","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-6809-2285","authenticated-orcid":false,"given":"Shahina","family":"Kunhimon","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7663-7161","authenticated-orcid":false,"given":"Muzammal","family":"Naseer","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4263-3143","authenticated-orcid":false,"given":"Fahad Shahbaz","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9502-1749","authenticated-orcid":false,"given":"Salman","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,21]]},"reference":[{"key":"23_CR1","doi-asserted-by":"crossref","unstructured":"Boyd, J., Liashuha, M., Deutsch, E., Paragios, N., Christodoulidis, S., Vakalopoulou, M.: Self-supervised representation learning using visual field expansion on digital pathology. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 639\u2013647 (2021)","DOI":"10.1109\/ICCVW54120.2021.00077"},{"key":"23_CR2","unstructured":"Brendel, W., Rauber, J., Bethge, M.: Decision-based adversarial attacks: reliable attacks against black-box machine learning models. In: International Conference on Learning Representations (ICLR) (2018)"},{"key":"23_CR3","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards evaluating the robustness of neural networks. In: 2017 IEEE symposium on security and privacy (SP), pp. 39\u201357. IEEE (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"23_CR4","doi-asserted-by":"crossref","unstructured":"Chen, P.Y., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.J.: Zoo: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security (2017)","DOI":"10.1145\/3128572.3140448"},{"issue":"3","key":"23_CR5","doi-asserted-by":"publisher","first-page":"850","DOI":"10.1038\/s41591-024-02857-3","volume":"30","author":"RJ Chen","year":"2024","unstructured":"Chen, R.J., et al.: Towards a general-purpose foundation model for computational pathology. Nat. Med. 30(3), 850\u2013862 (2024)","journal-title":"Nat. Med."},{"key":"23_CR6","unstructured":"Chen, R.J., Krishnan, R.G.: Self-supervised vision transformers learn visual concepts in histopathology. arXiv preprint arXiv:2203.00585 (2022)"},{"key":"23_CR7","doi-asserted-by":"publisher","unstructured":"Ciga, O., Xu, T., Martel, A.L.: Self supervised contrastive learning for digital histopathology. Mach. Learn. App. 7, 100198 (2022). https:\/\/doi.org\/10.1016\/j.mlwa.2021.100198, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2666827021000992","DOI":"10.1016\/j.mlwa.2021.100198"},{"key":"23_CR8","volume":"7","author":"O Ciga","year":"2022","unstructured":"Ciga, O., Xu, T., Martel, A.L.: Self supervised contrastive learning for digital histopathology. Mach. Learn. App. 7, 100198 (2022)","journal-title":"Mach. Learn. App."},{"key":"23_CR9","unstructured":"Croce, F., Hein, M.: Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In: International Conference on Machine Learning, pp. 2206\u20132216. PMLR (2020)"},{"key":"23_CR10","doi-asserted-by":"crossref","unstructured":"Dong, Y., et al.: Boosting adversarial attacks with momentum. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR) (2018)","DOI":"10.1109\/CVPR.2018.00957"},{"key":"23_CR11","first-page":"21480","volume":"34","author":"L Fan","year":"2021","unstructured":"Fan, L., Liu, S., Chen, P.Y., Zhang, G., Gan, C.: When does contrastive learning preserve adversarial robustness from pretraining to finetuning? Adv. Neural. Inf. Process. Syst. 34, 21480\u201321492 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"23_CR12","unstructured":"Foote, A., Asif, A., Azam, A., Marshall-Cox, T., Rajpoot, N., Minhas, F.: Now you see it, now you don\u2019t: adversarial vulnerabilities in computational pathology. arXiv preprint arXiv:2106.08153 (2021)"},{"issue":"1","key":"23_CR13","doi-asserted-by":"publisher","first-page":"5711","DOI":"10.1038\/s41467-022-33266-0","volume":"13","author":"N Ghaffari Laleh","year":"2022","unstructured":"Ghaffari Laleh, N., et al.: Adversarial attacks and adversarial robustness in computational pathology. Nat. Commun. 13(1), 5711 (2022)","journal-title":"Nat. Commun."},{"key":"23_CR14","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"23_CR15","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. corr abs\/1512.03385 (2015)"},{"key":"23_CR16","first-page":"28502","volume":"35","author":"C Jiang","year":"2022","unstructured":"Jiang, C., et al.: OpenSRH: optimizing brain tumor surgery using intraoperative stimulated Raman histology. Adv. Neural. Inf. Process. Syst. 35, 28502\u201328516 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"23_CR17","doi-asserted-by":"crossref","unstructured":"Jiang, C., et al.: Hierarchical discriminative learning improves visual representations of biomedical microscopy. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 19798\u201319808 (2023)","DOI":"10.1109\/CVPR52729.2023.01896"},{"key":"23_CR18","doi-asserted-by":"publisher","unstructured":"Kanca, E., Gulsoy, T., Ayas, S., Kablan, E.B.: Generating robust adversarial images in medical image classification using GANs. In: 2024 Innovations in Intelligent Systems and Applications Conference (ASYU), pp.\u00a01\u20135 (2024). https:\/\/doi.org\/10.1109\/ASYU62119.2024.10757024","DOI":"10.1109\/ASYU62119.2024.10757024"},{"key":"23_CR19","first-page":"2983","volume":"33","author":"M Kim","year":"2020","unstructured":"Kim, M., Tack, J., Hwang, S.J.: Adversarial self-supervised contrastive learning. Adv. Neural. Inf. Process. Syst. 33, 2983\u20132994 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"23_CR20","doi-asserted-by":"publisher","unstructured":"Kumar, D., Sharma, A., Narayan, A.: Attacking CNNs in histopathology with snap: Sporadic and naturalistic adversarial patches (student abstract). Proc. AAAI Conf. Artif. Intell. 38(2121), 23550\u201323551 (2024). https:\/\/doi.org\/10.1609\/aaai.v38i21.30468, https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/30468","DOI":"10.1609\/aaai.v38i21.30468"},{"key":"23_CR21","doi-asserted-by":"crossref","unstructured":"Kurakin, A., Goodfellow, I.J., Bengio, S.: Adversarial examples in the physical world. In: Artificial Intelligence Safety and Security, pp. 99\u2013112. Chapman and Hall\/CRC (2018)","DOI":"10.1201\/9781351251389-8"},{"key":"23_CR22","unstructured":"Loshchilov, I., Hutter, F.: Decoupled weight decay regularization. arXiv preprint arXiv:1711.05101 (2017)"},{"key":"23_CR23","unstructured":"Luo, R., Wang, Y., Wang, Y.: Rethinking the effect of data augmentation in adversarial contrastive learning. arXiv preprint arXiv:2303.01289 (2023)"},{"key":"23_CR24","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A.: Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083 (2017)"},{"issue":"10","key":"23_CR25","doi-asserted-by":"publisher","first-page":"2545","DOI":"10.3390\/biomedicines10102545","volume":"10","author":"TV Maliamanis","year":"2022","unstructured":"Maliamanis, T.V., Apostolidis, K.D., Papakostas, G.A.: How resilient are deep learning models in medical image analysis? the case of the moment-based adversarial attack (MB-ADA). Biomedicines 10(10), 2545 (2022)","journal-title":"Biomedicines"},{"key":"23_CR26","unstructured":"Malik, H.S., Kunhimon, S.K., Naseer, M., Khan, S., Khan, F.S.: Adversarial pixel restoration as a pretext task for transferable perturbations. arXiv preprint arXiv:2207.08803 (2022)"},{"key":"23_CR27","doi-asserted-by":"crossref","unstructured":"Narodytska, N., Kasiviswanathan, S.: Simple black-box adversarial attacks on deep neural networks. In: Computer Vision and Pattern Recognition (CVPR) Workshop (2017)","DOI":"10.1109\/CVPRW.2017.172"},{"key":"23_CR28","unstructured":"Naseer, M.M., Khan, S.H., Khan, M.H., Shahbaz\u00a0Khan, F., Porikli, F.: Cross-domain transferability of adversarial perturbations. In: Advances in Neural Information Processing Systems (NeurIPS) (2019)"},{"issue":"5","key":"23_CR29","doi-asserted-by":"publisher","first-page":"828","DOI":"10.1109\/TEVC.2019.2890858","volume":"23","author":"J Su","year":"2019","unstructured":"Su, J., Vargas, D.V., Sakurai, K.: One pixel attack for fooling deep neural networks. IEEE Trans. Evol. Comput. 23(5), 828\u2013841 (2019)","journal-title":"IEEE Trans. Evol. Comput."},{"key":"23_CR30","unstructured":"Szegedy, C., et al.: Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)"},{"key":"23_CR31","unstructured":"Wong, E., Rice, L., Kolter, J.Z.: Fast is better than free: revisiting adversarial training. arXiv preprint arXiv:2001.03994 (2020)"},{"key":"23_CR32","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S., Komodakis, N.: Wide residual networks. arXiv preprint arXiv:1605.07146 (2016)","DOI":"10.5244\/C.30.87"},{"key":"23_CR33","unstructured":"Zhang, H., Yu, Y., Jiao, J., Xing, E., El\u00a0Ghaoui, L., Jordan, M.: Theoretically principled trade-off between robustness and accuracy. In: International Conference on Machine Learning, pp. 7472\u20137482. PMLR (2019)"}],"container-title":["Lecture Notes in Computer Science","Medical Image Computing and Computer Assisted Intervention \u2013 MICCAI 2025"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-04927-8_23","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,20]],"date-time":"2025-09-20T17:09:07Z","timestamp":1758388147000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-04927-8_23"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,21]]},"ISBN":["9783032049261","9783032049278"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-04927-8_23","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025,9,21]]},"assertion":[{"value":"21 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"MICCAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Medical Image Computing and Computer-Assisted Intervention","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Daejeon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"miccai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conferences.miccai.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}