{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,22]],"date-time":"2026-03-22T06:46:25Z","timestamp":1774161985934,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":41,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,20]],"date-time":"2023-11-20T00:00:00Z","timestamp":1700438400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Zuckerman STEM Leadership Program"},{"name":"Horizon 2020","award":["952172"],"award-info":[{"award-number":["952172"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,20]]},"DOI":"10.1145\/3689942.3694746","type":"proceedings-article","created":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T00:21:45Z","timestamp":1732234905000},"page":"37-44","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["The Security of Deep Learning Defenses in Medical Imaging"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5061-4404","authenticated-orcid":false,"given":"Moshe","family":"Levy","sequence":"first","affiliation":[{"name":"Bar-Ilan University, Ramat-gan, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5987-4402","authenticated-orcid":false,"given":"Guy","family":"Amit","sequence":"additional","affiliation":[{"name":"Ben-Gurion University, Beersheva, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9641-128X","authenticated-orcid":false,"given":"Yuval","family":"Elovici","sequence":"additional","affiliation":[{"name":"Ben Gurion University, Beersheva, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6367-2734","authenticated-orcid":false,"given":"Yisroel","family":"Mirsky","sequence":"additional","affiliation":[{"name":"Ben-Gurion University, Beersheva, Israel"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00759"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-021-10125-w"},{"key":"e_1_3_2_1_3_1","volume-title":"Wagner","author":"Athalye Anish","year":"2018","unstructured":"Anish Athalye, Nicholas Carlini, and David A. Wagner. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In ICML."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI.2019.8759176"},{"key":"e_1_3_2_1_5_1","unstructured":"Christiaan Beek. 2018. McAfee Researchers Find Poor Security Exposes Medical Data to Cybercriminals | McAfee Blogs. https:\/\/www.mcafee.com\/blogs\/other-blogs\/mcafee-labs\/mcafee-researchers-find-poor-security-exposes-medical-data-to-cybercriminals. (Accessed on 11\/06\/2021)."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1148\/radiol.2018184007"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1098\/rsif.2017.0387"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI.2018.8363547"},{"key":"e_1_3_2_1_10_1","volume-title":"International conference on machine learning. PMLR, 2206--2216","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International conference on machine learning. PMLR, 2206--2216."},{"key":"e_1_3_2_1_11_1","volume-title":"Multi-task Learning for Detection and Classification of Cancer in Screening Mammography. In International Conference on Medical Image Computing and Computer-Assisted Intervention. Springer, 241--250","author":"Sainz de Cea Maria V","year":"2020","unstructured":"Maria V Sainz de Cea, Karl Diedrich, Ran Bakalo, Lior Ness, and David Richmond. 2020. Multi-task Learning for Detection and Classification of Cancer in Screening Mammography. In International Conference on Medical Image Computing and Computer-Assisted Intervention. Springer, 241--250."},{"key":"e_1_3_2_1_12_1","volume-title":"Adversarial Attacks Against Medical Deep Learning Systems. (04","author":"Finlayson Samuel","year":"2018","unstructured":"Samuel Finlayson, Isaac Kohane, and Andrew Beam. 2018. Adversarial Attacks Against Medical Deep Learning Systems. (04 2018)."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"key":"e_1_3_2_1_14_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_16_1","volume-title":"11th $$USENIX$$ workshop on offensive technologies ($$WOOT$$ 17).","author":"He Warren","unstructured":"Warren He, James Wei, Xinyun Chen, Nicholas Carlini, and Dawn Song. 2017. Adversarial example defense: Ensembles of weak defenses are not strong. In 11th $$USENIX$$ workshop on offensive technologies ($$WOOT$$ 17)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cell.2018.02.010"},{"key":"e_1_3_2_1_18_1","volume-title":"Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236","author":"Kurakin Alexey","year":"2016","unstructured":"Alexey Kurakin, Ian Goodfellow, and Samy Bengio. 2016. Adversarial machine learning at scale. arXiv preprint arXiv:1611.01236 (2016)."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI48211.2021.9433761"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098628"},{"key":"e_1_3_2_1_21_1","volume-title":"Arnaud Arindra Adiyoso Setio, Francesco Ciompi, Mohsen Ghafoorian, Jeroen Awm Van Der Laak, Bram Van Ginneken, and Clara I S\u00e1nchez.","author":"Litjens Geert","year":"2017","unstructured":"Geert Litjens, Thijs Kooi, Babak Ehteshami Bejnordi, Arnaud Arindra Adiyoso Setio, Francesco Ciompi, Mohsen Ghafoorian, Jeroen Awm Van Der Laak, Bram Van Ginneken, and Clara I S\u00e1nchez. 2017. A survey on deep learning in medical image analysis. Medical image analysis, Vol. 42 (2017), 60--88."},{"key":"e_1_3_2_1_22_1","unstructured":"Yanpei Liu Xinyun Chen Chang Liu and D. Song. 2017. Delving into Transferable Adversarial Examples and Black-box Attacks. ArXiv Vol. abs\/1611.02770 (2017)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"e_1_3_2_1_24_1","volume-title":"International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_25_1","volume-title":"28th $$USENIX$$ Security Symposium ($$USENIX$$ Security 19). 461--478.","author":"Mirsky Yisroel","unstructured":"Yisroel Mirsky, Tom Mahler, Ilan Shelef, and Yuval Elovici. 2019. CT-GAN: Malicious tampering of 3D medical imagery using deep learning. In 28th $$USENIX$$ Security Symposium ($$USENIX$$ Security 19). 461--478."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_1_27_1","unstructured":"NEMA. 2001. NEMA Standards Publication PS 3 Supplement 41 | Digital Imaging and Communications in Medicine (DICOM) Digital Signatures. https:\/\/www.dicomstandard.org\/News-dir\/ftsup\/docs\/sups\/sup41.pdf."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3595292"},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.41"},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098740"},{"key":"e_1_3_2_1_31_1","unstructured":"Foritfied Health Security. 2021. 2021 Horizon Report The State of Cybersecurity in Healthcare."},{"key":"e_1_3_2_1_32_1","volume-title":"Moira SN Berens, Cas Van Den Bogaard, Piergiorgio Cerello, Hao Chen, Qi Dou, Maria Evelina Fantacci, Bram Geurts, et al.","author":"Adiyoso Setio Arnaud Arindra","year":"2017","unstructured":"Arnaud Arindra Adiyoso Setio, Alberto Traverso, Thomas De Bel, Moira SN Berens, Cas Van Den Bogaard, Piergiorgio Cerello, Hao Chen, Qi Dou, Maria Evelina Fantacci, Bram Geurts, et al. 2017. Validation, comparison, and combination of algorithms for automatic detection of pulmonary nodules in computed tomography images: the LUNA16 challenge. Medical image analysis, Vol. 42 (2017), 1--13."},{"key":"e_1_3_2_1_33_1","unstructured":"Ran Shadmi Victoria Mazo Orna Bregman-Amitai and Eldad Elnekave. [n. d.]. FULLY-AUTOMATIC DEEP LEARNING BASED SYSTEM FOR AGATSTON SCORE PREDICTION FROM ANY NON-CONTRAST CHEST CT. ( [n. d.])."},{"key":"e_1_3_2_1_34_1","volume-title":"Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199","author":"Szegedy Christian","year":"2013","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus. 2013. Intriguing properties of neural networks. arXiv preprint arXiv:1312.6199 (2013)."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01160"},{"key":"e_1_3_2_1_36_1","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020","author":"Tram\u00e8r Florian","year":"2020","unstructured":"Florian Tram\u00e8r, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On Adaptive Attacks to Adversarial Example Defenses. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6--12, 2020, virtual, Hugo Larochelle, Marc'Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/11f38f8ecd71867b42433548d1078e38-Abstract.html"},{"key":"e_1_3_2_1_37_1","volume-title":"Bram van Ginneken, and Maarten de Rooij.","author":"van Leeuwen Kicky G","year":"2021","unstructured":"Kicky G van Leeuwen, Steven Schalekamp, Matthieu JCM Rutten, Bram van Ginneken, and Maarten de Rooij. 2021. Artificial intelligence in radiology: 100 commercially available products and their scientific evidence. European radiology, Vol. 31, 6 (2021), 3797--3804."},{"key":"e_1_3_2_1_38_1","volume-title":"A survey on physical adversarial attack in computer vision. arXiv preprint arXiv:2209.14262","author":"Wang Donghua","year":"2022","unstructured":"Donghua Wang, Wen Yao, Tingsong Jiang, Guijian Tang, and Xiaoqian Chen. 2022. A survey on physical adversarial attack in computer vision. arXiv preprint arXiv:2209.14262 (2022)."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.2214\/AJR.20.23250"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32226-7_94"},{"key":"e_1_3_2_1_41_1","unstructured":"Honggang Yu Kaichen Yang Teng Zhang Yun-Yun Tsai Tsung-Yi Ho and Yier Jin. 2020. CloudLeak: Large-Scale Deep Learning Models Stealing Through Adversarial Examples.. In NDSS."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2024 Workshop on Cybersecurity in Healthcare"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689942.3694746","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689942.3694746","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T02:29:39Z","timestamp":1755916179000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689942.3694746"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,20]]},"references-count":41,"alternative-id":["10.1145\/3689942.3694746","10.1145\/3689942"],"URL":"https:\/\/doi.org\/10.1145\/3689942.3694746","relation":{},"subject":[],"published":{"date-parts":[[2023,11,20]]},"assertion":[{"value":"2024-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}