{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,17]],"date-time":"2026-01-17T19:29:10Z","timestamp":1768678150187,"version":"3.49.0"},"reference-count":32,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2021,9,20]],"date-time":"2021-09-20T00:00:00Z","timestamp":1632096000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2021,9,20]],"date-time":"2021-09-20T00:00:00Z","timestamp":1632096000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000070","name":"National Institute of Biomedical Imaging and Bioengineering","doi-asserted-by":"publisher","award":["R01EB026708"],"award-info":[{"award-number":["R01EB026708"]}],"id":[{"id":"10.13039\/100000070","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000070","name":"National Institute of Biomedical Imaging and Bioengineering","doi-asserted-by":"publisher","award":["R01LM013151"],"award-info":[{"award-number":["R01LM013151"]}],"id":[{"id":"10.13039\/100000070","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Digit Imaging"],"published-print":{"date-parts":[[2021,10]]},"DOI":"10.1007\/s10278-021-00507-5","type":"journal-article","created":{"date-parts":[[2021,9,20]],"date-time":"2021-09-20T18:21:11Z","timestamp":1632162071000},"page":"1279-1293","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":16,"title":["Robustifying Deep Networks for Medical Image Segmentation"],"prefix":"10.1007","volume":"34","author":[{"given":"Zheng","family":"Liu","sequence":"first","affiliation":[]},{"given":"Jinnian","family":"Zhang","sequence":"additional","affiliation":[]},{"given":"Varun","family":"Jog","sequence":"additional","affiliation":[]},{"given":"Po-Ling","family":"Loh","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4502-6522","authenticated-orcid":false,"given":"Alan B.","family":"McMillan","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2021,9,20]]},"reference":[{"key":"507_CR1","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1016\/j.media.2016.06.032","volume":"33","author":"M de Bruijne","year":"2016","unstructured":"de Bruijne, M., 2016. Machine learning approaches in medical image analysis: From detection to diagnosis. Medical Image Analysis 33, 94\u201397. https:\/\/doi.org\/10.1016\/j.media.2016.06.032.","journal-title":"Medical Image Analysis"},{"key":"507_CR2","doi-asserted-by":"publisher","first-page":"933","DOI":"10.1016\/j.media.2012.02.005","volume":"16","author":"S Wang","year":"2012","unstructured":"Wang, S., Summers, R.M., 2012. Machine learning and radiology. Medical Image Analysis 16, 933\u2013951. https:\/\/doi.org\/10.1016\/j.media.2012.02.005.","journal-title":"Medical Image Analysis"},{"key":"507_CR3","doi-asserted-by":"publisher","unstructured":"Wernick, M., Yang, Y., Brankov, J., Yourganov, G., Strother, S., 2010. Machine Learning in Medical Imaging. IEEE signal processing magazine 27, 25\u201338. URL: http:\/\/ieeexplore.ieee.org\/document\/5484160\/, https:\/\/doi.org\/10.1109\/MSP.2010.936730.","DOI":"10.1109\/MSP.2010.936730"},{"key":"507_CR4","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y Lecun","year":"2015","unstructured":"Lecun, Y., Bengio, Y., Hinton, G., 2015. Deep learning. Nature 521, 436\u2013444. https:\/\/doi.org\/10.1038\/nature14539.","journal-title":"Nature"},{"key":"507_CR5","unstructured":"Lipton, Z.C., 2016. The Mythos of Model Interpretability, in: arXiv preprint. URL: http:\/\/arxiv.org\/abs\/1606.03490 , arXiv:1606.03490."},{"key":"507_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.dsp.2017.10.011","volume":"73","author":"G Montavon","year":"2018","unstructured":"Montavon, G., Samek, W., M\u00fcller, K.R., 2018. Methods for interpreting and understanding deep neural networks. Digital Signal Processing: A Review Journal 73, 1\u201315. https:\/\/doi.org\/10.1016\/j.dsp.2017.10.011.","journal-title":"Digital Signal Processing: A Review Journal"},{"key":"507_CR7","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C., 2014. Explaining and Harnessing Adversarial Examples, in: arXiv preprint. URL: http:\/\/arxiv.org\/abs\/1412.6572 , arXiv:1412.6572."},{"key":"507_CR8","unstructured":"Finlayson, S.G., Chung, H.W., Kohane, I.S., Beam, A.L., 2018. Adversarial Attacks Against Medical Deep Learning Systems, in: arXiv preprint. URL: http:\/\/arxiv.org\/abs\/1804.05296 , arXiv:1804.05296."},{"key":"507_CR9","doi-asserted-by":"publisher","unstructured":"Paschali, M., Conjeti, S., Navarro, F., Navab, N., 2018. Generalizability vs. robustness: Investigating medical imaging networks using adversarial examples, in: Proceedings of the Medical Image Computing and Computer-Assisted Intervention, Springer Verlag. pp. 493\u2013501. https:\/\/doi.org\/10.1007\/978-3-030-00928-1_56.","DOI":"10.1007\/978-3-030-00928-1_56"},{"key":"507_CR10","doi-asserted-by":"crossref","unstructured":"Ozbulak, U., Van Messem, A., De Neve, W., 2019. Impact of Adversarial Examples on Deep Learning Models for Biomedical Image Segmentation, in: Proceedings of the Medical Image Computing and Computer- Assisted Intervention. URL: http:\/\/arxiv.org\/abs\/1907.13124 , arXiv:1907.13124.","DOI":"10.1007\/978-3-030-32245-8_34"},{"key":"507_CR11","unstructured":"Kurakin, A., Goodfellow, I., Bengio, S., 2016. Adversarial Machine Learning at Scale, in: International Conference on Learning Representations. URL: http:\/\/arxiv.org\/abs\/1611.01236 , arXiv:1611.01236."},{"key":"507_CR12","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., Vladu, A., 2017. Towards Deep Learning Models Resistant to Adversarial Attacks, in: International Conference on Learning Representations. URL: http:\/\/arxiv.org\/abs\/1706.06083 , arXiv:1706.06083."},{"key":"507_CR13","doi-asserted-by":"publisher","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., Swami, A., 2016b. Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks, in: Proceedings of the IEEE Symposium on Security and Privacy, Institute of Electrical and Electronics Engineers Inc. pp. 582\u2013597. https:\/\/doi.org\/10.1109\/SP.2016.41.","DOI":"10.1109\/SP.2016.41"},{"key":"507_CR14","doi-asserted-by":"publisher","first-page":"14410","DOI":"10.1109\/ACCESS.2018.2807385","volume":"6","author":"N Akhtar","year":"2018","unstructured":"Akhtar, N., Mian, A., 2018. Threat of Adversarial Attacks on Deep Learning in Computer Vision: A Survey. IEEE Access 6, 14410\u201314430. https:\/\/doi.org\/10.1109\/ACCESS.2018.2807385.","journal-title":"IEEE Access"},{"key":"507_CR15","unstructured":"Bakas, S., 2017. Multimodal Brain Tumor Segmentation Challenge. URL: https:\/\/www.med.upenn.edu\/sbia\/brats2017\/data.html ."},{"key":"507_CR16","doi-asserted-by":"publisher","unstructured":"Bakas, S., Akbari, H., Sotiras, A., Bilello, M., Rozycki, M., Kirby, J.S., Freymann, J.B., Farahani, K., Davatzikos, C., 2017a. Advancing The Cancer Genome Atlas glioma MRI collections with expert seg- mentation labels and radiomic features. Scientific data 4, 170117. URL: http:\/\/www.ncbi.nlm.nih.gov\/pubmed\/28872634, https:\/\/doi.org\/10.1038\/sdata.2017.117.","DOI":"10.1038\/sdata.2017.117"},{"key":"507_CR17","doi-asserted-by":"publisher","unstructured":"Bakas, S., Akbari, H., Sotiras, A., Bilello, M., Rozycki, M., Kirby, J.S., Freymann, J.B., Farahani, K., Davatzikos, C., 2017b. Segmentation Labels and Radiomic Features for the Pre-operative Scans of the TCGA-GBM col- lection. URL: https:\/\/doi.org\/10.7937\/K9\/TCIA.2017.KLXWJJ1Q , https:\/\/doi.org\/10.7937\/K9\/TCIA.2017.KLXWJJ1Q.","DOI":"10.7937\/K9\/TCIA.2017.KLXWJJ1Q 10.7937\/K9\/TCIA.2017.KLXWJJ1Q"},{"key":"507_CR18","doi-asserted-by":"publisher","unstructured":"Bakas, S., Akbari, H., Sotiras, A., Bilello, M., Rozycki, M., Kirby, J.S., Freymann, J.B., Farahani, K., Davatzikos, C., 2017c. Segmentation Labels and Radiomic Features for the Pre-operative Scans of the TCGA-LGG collection [Data Set]. The Cancer Imaging Archive. https:\/\/doi.org\/10.7937\/K9\/TCIA.2017.GJQ7R0EF.","DOI":"10.7937\/K9\/TCIA.2017.GJQ7R0EF"},{"key":"507_CR19","doi-asserted-by":"publisher","first-page":"1993","DOI":"10.1109\/TMI.2014.2377694","volume":"34","author":"BH Menze","year":"2015","unstructured":"Menze, B.H., Jakab, A., Bauer, S., Kalpathy-Cramer, J., Farahani, K., Kirby, J., Burren, Y., Porz, N., Slotboom, J., Wiest, R., Lanczi, L., Gerstner, E., Weber, M.A., Arbel, T., Avants, B.B., Ayache, N., Buendia, P., Collins, D.L., Cordier, N., Corso, J.J., Criminisi, A., Das, T., Delingette, H., Demiralp, C., Durst, C.R., Dojat, M., Doyle, S., Festa, J., Forbes, F., Geremia, E., Glocker, B., Golland, P., Guo, X., Hamamci, A., Iftekharuddin, K.M., Jena, R., John, N.M., Konukoglu, E., Lashkari, D., Mariz, J.A., Meier, R., Pereira, S., Precup, D., Price, S.J., Raviv, T.R., Reza, S.M., Ryan, M., Sarikaya, D., Schwartz, L., Shin, H.C., Shotton, J., Silva, C.A., Sousa, N., Subbanna, N.K., Szekely, G., Taylor, T.J., Thomas, O.M., Tustison, N.J., Unal, G., Vasseur, F., Wintermark, M., Ye, D.H., Zhao, L., Zhao, B., Zikic, D., Prastawa, M., Reyes, M., Van Leemput, K., 2015. The Multimodal Brain Tumor Image Segmentation Benchmark (BRATS). IEEE Transactions on Medical Imaging 34, 1993\u20132024. https:\/\/doi.org\/10.1109\/TMI.2014.2377694.","journal-title":"IEEE Transactions on Medical Imaging"},{"key":"507_CR20","doi-asserted-by":"publisher","unstructured":"\u00c7i\u00e7ek, \u00d6., Abdulkadir, A., Lienkamp, S.S., Brox, T., Ronneberger, O., 2016. 3D U-net: Learning dense volumetric segmentation from sparse annotation, in: Proceedings of the Medical Image Computing and Computer- Assisted Intervention, Springer Verlag. pp. 424\u2013432. https:\/\/doi.org\/10.1007\/978-3-319-46723-8_49.","DOI":"10.1007\/978-3-319-46723-8_49"},{"key":"507_CR21","doi-asserted-by":"crossref","unstructured":"Ronneberger, O., Fischer, P. and Brox, T., 2015, October. U-net: Convolutional networks for biomedical image segmentation. In International Conference on Medical image computing and computer-assisted intervention (pp. 234\u2013241). Springer, Cham.","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"507_CR22","doi-asserted-by":"publisher","unstructured":"He, K., Zhang, X., Ren, S., Sun, J., 2016. Deep residual learning for image recognition, in: Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, IEEE Computer Society. pp. 770\u2013778. https:\/\/doi.org\/10.1109\/CVPR.2016.90.","DOI":"10.1109\/CVPR.2016.90"},{"key":"507_CR23","doi-asserted-by":"publisher","first-page":"178","DOI":"10.1016\/S1076-6332(03)00671-8","volume":"11","author":"KH Zou","year":"2004","unstructured":"Zou, K.H., Warfield, S.K., Bharatha, A., Tempany, C.M., Kaus, M.R., Haker, S.J., Wells, W.M., Jolesz, F.A., Kikinis, R., 2004. Statistical Validation of Image Segmentation Quality Based on a Spatial Overlap Index. Academic Radiology 11, 178\u2013189. https:\/\/doi.org\/10.1016\/S1076-6332(03)00671-8.","journal-title":"Academic Radiology"},{"key":"507_CR24","unstructured":"Carlini, N., Wagner, D., 2017. MagNet and \u201cEfficient Defenses Against Adversarial Attacks\u201d are Not Robust to Adversarial Examples, in: arXiv preprint. URL: https:\/\/github.com\/carlini\/MagNet , arXiv:1711.08478v1."},{"key":"507_CR25","unstructured":"Engstrom, L., Tran, B., Tsipras, D., Schmidt, L., Madry, A., 2019. Exploring the Landscape of Spatial Robustness. Proceedings of Machine Learning Research 97, 1802\u20131811. URL: http:\/\/arxiv.org\/abs\/1712.02779 , arXiv:1712.02779."},{"key":"507_CR26","doi-asserted-by":"publisher","unstructured":"Zantedeschi, V., Nicolae, M.I., Rawat, A., 2017. Efficient defenses against adversarial attacks, in: Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, co-located with CCS 2017, Association for Computing Machinery, Inc. pp. 39\u201349. https:\/\/doi.org\/10.1145\/3128572.3140449.","DOI":"10.1145\/3128572.3140449"},{"key":"507_CR27","doi-asserted-by":"publisher","first-page":"1310","DOI":"10.1109\/TMI.2010.2046908","volume":"29","author":"NJ Tustison","year":"2010","unstructured":"Tustison, N.J., Avants, B.B., Cook, P.A., Zheng, Y., Egan, A., Yushkevich, P.A., Gee, J.C., 2010. N4ITK: Improved N3 bias correction. IEEE Transactions on Medical Imaging 29, 1310\u20131320. https:\/\/doi.org\/10.1109\/TMI.2010.2046908.","journal-title":"IEEE Transactions on Medical Imaging"},{"key":"507_CR28","unstructured":"Liu, Y., Chen, X., Liu, C., Song, D., 2016. Delving into Transferable Adversarial Examples and Black-box Attacks, in: International Conference on Learning Representations. URL: http:\/\/arxiv.org\/abs\/1611.02770 , arXiv:1611.02770."},{"key":"507_CR29","doi-asserted-by":"publisher","unstructured":"Papernot, N., McDaniel, P., Goodfellow, I., Jha, S., Celik, Z.B., Swami, A., 2017. Practical black-box attacks against machine learning, in: Proceedings of the 2017 ACM Asia Conference on Computer and Communications Security, Association for Computing Machinery, Inc. pp. 506\u2013519. https:\/\/doi.org\/10.1145\/3052973.3053009.","DOI":"10.1145\/3052973.3053009"},{"key":"507_CR30","doi-asserted-by":"publisher","unstructured":"Moosavi-Dezfooli, S.M., Fawzi, A., Frossard, P., 2016. DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks, in: Proceedings of the IEEE Computer Society Conference on Computer Vision and Pattern Recognition, IEEE Computer Society. pp. 2574\u20132582. https:\/\/doi.org\/10.1109\/CVPR.2016.282.","DOI":"10.1109\/CVPR.2016.282"},{"key":"507_CR31","doi-asserted-by":"publisher","unstructured":"Papernot, N., Mcdaniel, P., Jha, S., Fredrikson, M., Celik, Z.B., Swami, A., 2016a. The limitations of deep learning in adversarial settings, in: Proceedings of the IEEE European Symposium on Security and Privacy, EURO S and P 2016, Institute of Electrical and Electronics Engineers Inc. pp. 372\u2013 387. https:\/\/doi.org\/10.1109\/EuroSP.2016.36.","DOI":"10.1109\/EuroSP.2016.36"},{"key":"507_CR32","doi-asserted-by":"publisher","unstructured":"Xie, C., Wang, J., Zhang, Z., Zhou, Y., Xie, L., Yuille, A., 2017. Adversarial Examples for Semantic Segmentation and Object Detection, in: Proceedings of the IEEE International Conference on Computer Vision, Institute of Electrical and Electronics Engineers Inc. pp. 1378\u20131387. https:\/\/doi.org\/10.1109\/ICCV.2017.153.","DOI":"10.1109\/ICCV.2017.153"}],"container-title":["Journal of Digital Imaging"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10278-021-00507-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10278-021-00507-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10278-021-00507-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,27]],"date-time":"2021-10-27T21:06:08Z","timestamp":1635368768000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10278-021-00507-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,9,20]]},"references-count":32,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2021,10]]}},"alternative-id":["507"],"URL":"https:\/\/doi.org\/10.1007\/s10278-021-00507-5","relation":{},"ISSN":["0897-1889","1618-727X"],"issn-type":[{"value":"0897-1889","type":"print"},{"value":"1618-727X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,9,20]]},"assertion":[{"value":"14 July 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"4 July 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"17 August 2021","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 September 2021","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of Interest"}}]}}