{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T15:59:23Z","timestamp":1784995163538,"version":"3.55.0"},"reference-count":226,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T00:00:00Z","timestamp":1732233600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["12326618, 62072482, and 62202403"],"award-info":[{"award-number":["12326618, 62072482, and 62202403"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100007156","name":"Hong Kong Innovation and Technology Fund","doi-asserted-by":"crossref","award":["ITS\/028\/21FP and MHP\/002\/22"],"award-info":[{"award-number":["ITS\/028\/21FP and MHP\/002\/22"]}],"id":[{"id":"10.13039\/501100007156","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Shenzhen Science and Technology Innovation Committee Fund","award":["SGDX20210823103201011"],"award-info":[{"award-number":["SGDX20210823103201011"]}]},{"name":"Project of Guangdong Provincial Key Laboratory of Information Security Technology","award":["2023B1212060026"],"award-info":[{"award-number":["2023B1212060026"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,3,31]]},"abstract":"<jats:p>\n            Deep learning techniques have achieved superior performance in computer-aided medical image analysis, yet they are still vulnerable to imperceptible adversarial attacks, resulting in potential misdiagnosis in clinical practice. Oppositely, recent years have also witnessed remarkable progress in defense against these tailored adversarial examples in deep medical diagnosis systems. In this exposition, we present a comprehensive survey on recent advances in adversarial attacks and defenses for medical image analysis with a systematic taxonomy in terms of the application scenario. We also provide a unified framework for different types of adversarial attack and defense methods in the context of medical image analysis. For a fair comparison, we establish a new benchmark for adversarially robust medical diagnosis models obtained by adversarial training under various scenarios. To the best of our knowledge, this is the first survey article that provides a thorough evaluation of adversarially robust medical diagnosis models. By analyzing qualitative and quantitative results, we conclude this survey with a detailed discussion of current challenges for adversarial attack and defense in medical image analysis systems to shed light on future research directions. Code is available on\n            <jats:styled-content style=\"color:#FF0000\">GitHub<\/jats:styled-content>\n            .\n          <\/jats:p>","DOI":"10.1145\/3702638","type":"journal-article","created":{"date-parts":[[2024,10,30]],"date-time":"2024-10-30T09:55:51Z","timestamp":1730282151000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":47,"title":["Survey on Adversarial Attack and Defense for Medical Image Analysis: Methods and Challenges"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6232-9157","authenticated-orcid":false,"given":"Junhao","family":"Dong","sequence":"first","affiliation":[{"name":"Key Laboratory of Information Security Technology, Sun Yat-Sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-2512-4438","authenticated-orcid":false,"given":"Junxi","family":"Chen","sequence":"additional","affiliation":[{"name":"Key Laboratory of Information Security Technology, Sun Yat-Sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0310-4679","authenticated-orcid":false,"given":"Xiaohua","family":"Xie","sequence":"additional","affiliation":[{"name":"Key Laboratory of Information Security Technology, Sun Yat-Sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3883-2024","authenticated-orcid":false,"given":"Jianhuang","family":"Lai","sequence":"additional","affiliation":[{"name":"Key Laboratory of Information Security Technology, Sun Yat-Sen University, Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8400-3780","authenticated-orcid":false,"given":"Hao","family":"Chen","sequence":"additional","affiliation":[{"name":"The Hong Kong University of Science and Technology, Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,22]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.3389\/fmedt.2022.919046"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-04826-5_60"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-021-10125-w"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1097\/MD.0000000000023568"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-16437-8_36"},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cmpbup.2021.100025"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098369"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58592-1_29"},{"key":"e_1_3_2_10_2","first-page":"16048","article-title":"Understanding and improving fast adversarial training","volume":"33","author":"Andriushchenko Maksym","year":"2020","unstructured":"Maksym Andriushchenko and Nicolas Flammarion. 2020. Understanding and improving fast adversarial training. Advan. Neural Inf. Process. Syst. 33 (2020), 16048\u201316059.","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.3390\/electronics10172132"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.3390\/jimaging8060155"},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-02628-8_10"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2016.2644615"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.109037"},{"key":"e_1_3_2_16_2","volume-title":"International Conference on Computational Intelligence in Data Science","author":"Kumar D. P. Bharath","year":"2022","unstructured":"D. P. Bharath Kumar, Nanda Kumar, Snofy D. Dunston, and V. Rajam. 2022. Analysis of the impact of white box adversarial attacks in ResNet while classifying retinal fundus images. In International Conference on Computational Intelligence in Data Science."},{"key":"e_1_3_2_17_2","first-page":"162","volume-title":"International Conference on Computational Intelligence in Data Science","author":"Kumar D. P. Bharath","year":"2022","unstructured":"D. P. Bharath Kumar, Nanda Kumar, Snofy D. Dunston, and V. Mary Anita Rajam. 2022. Analysis of the impact of white box adversarial attacks in ResNet while classifying retinal fundus images. In International Conference on Computational Intelligence in Data Science(ICCIDS\u201922) . 162\u2013175."},{"key":"e_1_3_2_18_2","first-page":"528","volume-title":"International Conference on Intelligent Computing Instrumentation and Control Technologies","year":"2022","unstructured":"Pranava Raman B M S, Anusree V, Sreeratcha B, Preeti Krishnaveni Ra, Snofy D. Dunston, and Mary Anita Rajam V. 2022. Analysis of the effect of black box adversarial attacks on medical image classification models. In International Conference on Intelligent Computing Instrumentation and Control Technologies(ICICICT\u201922). 528\u2013531."},{"key":"e_1_3_2_19_2","article-title":"Adversarial heart attack: Neural networks fooled to segment heart symbols in chest X-ray images","author":"Bortsova Gerda","year":"2021","unstructured":"Gerda Bortsova, Florian Dubost, Laurens Hogeweg, Ioannis Katramados, and Marleen de Bruijne. 2021. Adversarial heart attack: Neural networks fooled to segment heart symbols in chest X-ray images. arXiv preprint arXiv:2104.00139 (2021).","journal-title":"arXiv preprint arXiv:2104.00139"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2021.102141"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2020.101797"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/IUS46767.2020.9251568"},{"key":"e_1_3_2_23_2","article-title":"Trustworthy medical segmentation with uncertainty estimation","author":"Carannante Giuseppina","year":"2021","unstructured":"Giuseppina Carannante, Dimah Dera, Nidhal C. Bouaynaya, Ghulam Rasool, and Hassan M. Fathallah-Shaykh. 2021. Trustworthy medical segmentation with uncertainty estimation. arXiv preprint arXiv:2111.05978 (2021).","journal-title":"arXiv preprint arXiv:2111.05978"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140444"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.49"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2022.102597"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59710-8_65"},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compbiomed.2023.107248"},{"key":"e_1_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00045"},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1117\/12.2580852"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32778-1_10"},{"key":"e_1_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1002\/mp.15208"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"e_1_3_2_34_2","article-title":"RAE-VWP: A reversible adversarial example-based privacy and copyright protection method of medical images for internet of medical things","author":"Chen Zhen","year":"2024","unstructured":"Zhen Chen, Xiuli Chai, Zhihua Gan, Binjie Wang, and Yushu Zhang. 2024. RAE-VWP: A reversible adversarial example-based privacy and copyright protection method of medical images for internet of medical things. IEEE Internet Things J. 11, 11 (2024), 20757\u201320768.","journal-title":"IEEE Internet Things J."},{"key":"e_1_3_2_35_2","article-title":"Content-based unrestricted adversarial attack","volume":"36","author":"Chen Zhaoyu","year":"2024","unstructured":"Zhaoyu Chen, Bo Li, Shuang Wu, Kaixun Jiang, Shouhong Ding, and Wenqiang Zhang. 2024. Content-based unrestricted adversarial attack. Advan. Neural Inf. Process. Syst. 36 (2024).","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_2_36_2","article-title":"Adversarial perturbation on MRI modalities in brain tumor segmentation","volume":"8","author":"Cheng Guohua","year":"2020","unstructured":"Guohua Cheng and Hongli Ji. 2020. Adversarial perturbation on MRI modalities in brain tumor segmentation. IEEE Access 8 (2020).","journal-title":"IEEE Access"},{"key":"e_1_3_2_37_2","first-page":"121","volume-title":"Medical Imaging with Deep Learning","author":"Cheng Kaiyang","year":"2020","unstructured":"Kaiyang Cheng, Francesco Caliv\u00e1, Rutwik Shah, Misung Han, Sharmila Majumdar, and Valentina Pedoia. 2020. Addressing the false negative problem of deep learning MRI reconstruction models by adversarial attacks and robust training. In Medical Imaging with Deep Learning. PMLR, 121\u2013135."},{"key":"e_1_3_2_38_2","article-title":"Improving black-box adversarial attacks with a transfer-based prior","volume":"32","author":"Cheng Shuyu","year":"2019","unstructured":"Shuyu Cheng, Yinpeng Dong, Tianyu Pang, Hang Su, and Jun Zhu. 2019. Improving black-box adversarial attacks with a transfer-based prior. Advan. Neural Inf. Process. Syst. 32 (2019).","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_2_39_2","article-title":"Adversarial exposure attack on diabetic retinopathy imagery","author":"Cheng Yupeng","year":"2020","unstructured":"Yupeng Cheng, Felix Juefei-Xu, Qing Guo, Huazhu Fu, Xiaofei Xie, Shang-Wei Lin, Weisi Lin, and Yang Liu. 2020. Adversarial exposure attack on diabetic retinopathy imagery. arXiv preprint arXiv:2009.09231 (2020).","journal-title":"arXiv preprint arXiv:2009.09231"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISSNIP.2007.4496905"},{"key":"e_1_3_2_41_2","doi-asserted-by":"publisher","unstructured":"Muhammad E. H. Chowdhury Tawsifur Rahman Amith Khandakar Rashid Mazhar Muhammad Abdul Kadir Zaid Bin Mahbub Khandakar Reajul Islam Muhammad Salman Khan Atif Iqbal Nasser Al Emadi Mamun Bin Ibne Reaz and Mohammad Tariqul Islam. 2020. Can AI help in screening viral and COVID-19 pneumonia? IEEE Access 8 (2020) 132665\u2013132676. DOI:10.1109\/ACCESS.2020.3010287","DOI":"10.1109\/ACCESS.2020.3010287"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","unstructured":"Noel C. F. Codella David Gutman M. Emre Celebi Brian Helba Michael A. Marchetti Stephen W. Dusza Aadi Kalloo Konstantinos Liopyris Nabin Mishra Harald Kittler and Allan Halpern. 2018. Skin lesion analysis toward melanoma detection: A challenge at the 2017 international symposium on biomedical imaging (ISBI) hosted by the international skin imaging collaboration (ISIC). In 2018 IEEE 15th International Symposium on Biomedical Imaging (ISBI 2018) 168\u2013172. DOI:10.1109\/ISBI.2018.8363547","DOI":"10.1109\/ISBI.2018.8363547"},{"key":"e_1_3_2_43_2","volume-title":"Annual Conference on Neural Information Processing Systems (NeurIPS\u201921)","author":"Croce Francesco","year":"2021","unstructured":"Francesco Croce, Maksym Andriushchenko, Vikash Sehwag, Edoardo Debenedetti, Nicolas Flammarion, Mung Chiang, Prateek Mittal, and Matthias Hein. 2021. RobustBench: A standardized adversarial robustness benchmark. In Annual Conference on Neural Information Processing Systems (NeurIPS\u201921)."},{"key":"e_1_3_2_44_2","first-page":"2206","volume-title":"International Conference on Machine Learning","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In International Conference on Machine Learning(ICML\u201920). 2206\u20132216."},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.08.118"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3210179"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2021.108249"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compbiomed.2023.107251"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87199-4_1"},{"key":"e_1_3_2_50_2","volume-title":"Conference on Medical Imaging: Computer-Aided Diagnosis","author":"Aguiar Erikson J. de","year":"2022","unstructured":"Erikson J. de Aguiar, Karem D. Marcomini, Felipe A. Quirino, Marco A. Gutierrez, Caetano Traina Jr, and Agma J. M. Traina. 2022. Evaluation of the impact of physical adversarial attacks on deep learning models for classifying COVID cases. In Conference on Medical Imaging: Computer-Aided Diagnosis."},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","unstructured":"Etienne Decenci\u00e8re Xiwei Zhang Guy Cazuguel Bruno La\u00ff B\u00e9atrice Cochener Caroline Trone Philippe Gain John-Richard Ord\u00f3\u00f1ez-Varela Pascale Massin Ali Erginay B\u00e9atrice Charton and Jean-Claude Klein. 2014. Feedback on a publicly distributed image database: The Messidor database. Image Analysis & Stereology (2014). International Society for Stereology 231\u2013234. DOI:10.5566\/ias.1155","DOI":"10.5566\/ias.1155"},{"key":"e_1_3_2_52_2","first-page":"321","volume-title":"USENIX Security Symposium","author":"Demontis Ambra","year":"2019","unstructured":"Ambra Demontis, Marco Melis, Maura Pintor, Matthew Jagielski, Battista Biggio, Alina Oprea, Cristina Nita-Rotaru, and Fabio Roli. 2019. Why do adversarial attacks transfer? Explaining transferability of evasion and poisoning attacks. In USENIX Security Symposium. 321\u2013338."},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","unstructured":"Weiping Ding Chuansheng Liu Jiashuang Huang Chun Cheng and Hengrong Ju. 2024. ViTH-RFG: Vision transformer hashing with residual fuzzy generation for targeted attack in medical image retrieval. IEEE Transactions on Fuzzy Systems 32 10 (2024) 5571\u20135584. DOI:10.1109\/TFUZZ.2023.3343352","DOI":"10.1109\/TFUZZ.2023.3343352"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/EHB52898.2021.9657589"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02364"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3266702"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00882"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428173"},{"key":"e_1_3_2_59_2","unstructured":"FDA. 2018. FDA Permits Marketing of Artificial Intelligence-based Device to Detect Certain Diabetes-related Eye Problems. Retrieved from https:\/\/www.fda.gov\/news-events\/press-announcements\/fda-permits-marketing-artificial-intelligence-based-device-detect-certain-diabetes-related-eye"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.aaw4399"},{"key":"e_1_3_2_61_2","article-title":"Now you see it, now you don\u2019t: Adversarial vulnerabilities in computational pathology","author":"Foote Alex","year":"2021","unstructured":"Alex Foote, Amina Asif, Ayesha Azam, Tim Marshall-Cox, Nasir Rajpoot, and Fayyaz Minhas. 2021. Now you see it, now you don\u2019t: Adversarial vulnerabilities in computational pathology. arXiv preprint arXiv:2106.08153 (2021).","journal-title":"arXiv preprint arXiv:2106.08153"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-66179-7_29"},{"key":"e_1_3_2_63_2","article-title":"Adversarial attacks and adversarial robustness in computational pathology","volume":"13","author":"Laleh Narmin Ghaffari","year":"2022","unstructured":"Narmin Ghaffari Laleh, Daniel Truhn, Gregory Patrick Veldhuizen, Tianyu Han, Marko van Treeck, Roman D. Buelow, Rupert Langer, Bastian Dislich, Peter Boor, Volkmar Schulz, et\u00a0al. 2022. Adversarial attacks and adversarial robustness in computational pathology. Nat. Commun. 13 (2022).","journal-title":"Nat. Commun."},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i04.5816"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2017.8296646"},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1145\/3400302.3418782"},{"key":"e_1_3_2_67_2","volume-title":"International Conference on Learning Representations (ICLR\u201915)","author":"Goodfellow Ian J.","year":"2015","unstructured":"Ian J. Goodfellow, Jonathon Shlens, and Christian Szegedy. 2015. Explaining and harnessing adversarial examples. In International Conference on Learning Representations (ICLR\u201915)."},{"key":"e_1_3_2_68_2","doi-asserted-by":"crossref","unstructured":"Reza Amini Gougeh. 2021. How adversarial attacks affect deep neural networks detecting COVID-19? (2021).","DOI":"10.21203\/rs.3.rs-763355\/v1"},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-6636-0_9"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-021-24464-3"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_72_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33018417"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1186\/s12880-020-00530-y"},{"key":"e_1_3_2_74_2","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2024.3384970"},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.21037\/qims-21-1089"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00928-1_17"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICoDSA50139.2020.9212850"},{"key":"e_1_3_2_78_2","volume-title":"International Conference on Learning Representations (ICLR\u201919)","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Logan Engstrom, and Aleksander Madry. 2019. Prior convictions: Black-box adversarial attacks with bandits and priors. In International Conference on Learning Representations (ICLR\u201919)."},{"key":"e_1_3_2_79_2","article-title":"Adversarial examples are not bugs, they are features","volume":"32","author":"Ilyas Andrew","year":"2019","unstructured":"Andrew Ilyas, Shibani Santurkar, Dimitris Tsipras, Logan Engstrom, Brandon Tran, and Aleksander Madry. 2019. Adversarial examples are not bugs, they are features. Advan. Neural Inf. Process. Syst. 32 (2019).","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","unstructured":"Jeremy Irvin Pranav Rajpurkar Michael Ko Yifan Yu Silviana Ciurea-Ilcus Christopher Chute Henrik Marklund Behzad Haghgoo Robyn L. Ball Katie S. Shpanskaya Jayne Seekins David A. Mong Safwan S. Halabi Jesse K. Sandberg Ricky Jones David B. Larson Curtis P. Langlotz Bhavik N. Patel Matthew P. Lungren and Andrew Y. Ng. 2019. CheXpert: A large chest radiograph dataset with uncertainty labels and expert comparison. In The Thirty-Third AAAI Conference on Artificial Intelligence AAAI 2019 The Thirty-First Innovative Applications of Artificial Intelligence Conference IAAI 2019 The Ninth AAAI Symposium on Educational Advances in Artificial Intelligence EAAI 2019 Honolulu Hawaii USA January 27 - February 1 2019 AAAI Press 590\u2013597. DOI:10.1609\/AAAI.V33I01.3301590","DOI":"10.1609\/AAAI.V33I01.3301590"},{"key":"e_1_3_2_81_2","article-title":"RoS-KD: A robust stochastic knowledge distillation approach for noisy medical imaging","author":"Jaiswal Ajay","year":"2022","unstructured":"Ajay Jaiswal, Kumar Ashutosh, Justin F. Rousseau, Yifan Peng, Zhangyang Wang, and Ying Ding. 2022. RoS-KD: A robust stochastic knowledge distillation approach for noisy medical imaging. arXiv preprint arXiv:2210.08388 (2022).","journal-title":"arXiv preprint arXiv:2210.08388"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2019.00257"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/3343031.3351088"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","unstructured":"Marina Z. Joel Sachin Umrao Enoch Chang Rachel Choi Daniel Yang Antonio Omuro Roy Herbst Harlan Krumholz and Sanjay Aneja. 2021. Adversarial attack vulnerability of deep learning models for oncologic images. medRxiv (2021). DOI:10.1101\/2021.01.17.21249704","DOI":"10.1101\/2021.01.17.21249704"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1200\/CCI.21.00170"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.heliyon.2022.e11209"},{"key":"e_1_3_2_87_2","doi-asserted-by":"crossref","unstructured":"Sara Kaviani Ki Jin Han and Insoo Sohn. 2022. Adversarial attacks and defenses on AI in medical imaging informatics: A survey. Expert Systems with Applications 198 (2022) 116815.","DOI":"10.1016\/j.eswa.2022.116815"},{"key":"e_1_3_2_88_2","article-title":"Simple black-box universal adversarial attacks on medical image classification based on deep neural networks","author":"Koga Kazuki","year":"2021","unstructured":"Kazuki Koga and Kazuhiro Takemoto. 2021. Simple black-box universal adversarial attacks on medical image classification based on deep neural networks. arXiv preprint arXiv:2108.04979 (2021).","journal-title":"arXiv preprint arXiv:2108.04979"},{"key":"e_1_3_2_89_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-31964-9_17"},{"key":"e_1_3_2_90_2","doi-asserted-by":"crossref","unstructured":"V. A. Kovalev V. A. Liauchuk D. M. Voynov and A. V. Tuzikov. 2021. Biomedical image recognition in pulmonology and oncology with the use of deep learning. Pattern Recognition and Image Analysis 31 (2021) 144\u2013162.","DOI":"10.1134\/S1054661821010120"},{"key":"e_1_3_2_91_2","article-title":"Influence of control parameters and the size of biomedical image datasets on the success of adversarial attacks","author":"Kovalev Vassili","year":"2019","unstructured":"Vassili Kovalev and Dmitry Voynov. 2019. Influence of control parameters and the size of biomedical image datasets on the success of adversarial attacks. arXiv preprint arXiv:1904.06964 (2019).","journal-title":"arXiv preprint arXiv:1904.06964"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-81645-2_26"},{"key":"e_1_3_2_93_2","doi-asserted-by":"crossref","unstructured":"Hyun Kwon and Jongwook Jeong. 2022. AdvU-Net: Generating adversarial example based on medical image and targeting U-Net model. Journal of Sensors 2022 1 (2022) 4390413.","DOI":"10.1155\/2022\/4390413"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.3390\/s21113922"},{"key":"e_1_3_2_95_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-16876-5_7"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00019"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.3390\/app14062576"},{"key":"e_1_3_2_98_2","article-title":"The security of deep learning defences for medical imaging","author":"Levy Moshe","year":"2022","unstructured":"Moshe Levy, Guy Amit, Yuval Elovici, and Yisroel Mirsky. 2022. The security of deep learning defences for medical imaging. arXiv preprint arXiv:2201.08661 (2022).","journal-title":"arXiv preprint arXiv:2201.08661"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2022.03.008"},{"key":"e_1_3_2_100_2","article-title":"Dynamic perturbation-adaptive adversarial training on medical image classification","author":"Li Shuai","year":"2024","unstructured":"Shuai Li, Xiaoguang Ma, Shancheng Jiang, and Lu Meng. 2024. Dynamic perturbation-adaptive adversarial training on medical image classification. arXiv preprint arXiv:2403.06798 (2024).","journal-title":"arXiv preprint arXiv:2403.06798"},{"key":"e_1_3_2_101_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI48211.2021.9433761"},{"key":"e_1_3_2_102_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098628"},{"key":"e_1_3_2_103_2","doi-asserted-by":"publisher","DOI":"10.3390\/bioengineering10020194"},{"key":"e_1_3_2_104_2","doi-asserted-by":"crossref","unstructured":"Yi Li Huahong Zhang Camilo Bermudez Yifan Chen Bennett A. Landman and Yevgeniy Vorobeychik. 2020. Anatomical context protects deep learning from adversarial perturbations in medical imaging. Neurocomputing 379 (2020) 370\u2013378.","DOI":"10.1016\/j.neucom.2019.10.085"},{"key":"e_1_3_2_105_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-13969-8_4"},{"key":"e_1_3_2_106_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59719-1_34"},{"key":"e_1_3_2_107_2","doi-asserted-by":"crossref","unstructured":"Siqi Liu Arnaud Arindra Adiyoso Setio Florin C. Ghesu Eli Gibson Sasa Grbic Bogdan Georgescu and Dorin Comaniciu. 2020. No surprises: Training robust lung nodule detection for low-dose CT scans by augmenting with adversarial attacks. IEEE Transactions on Medical Imaging 40 1 (2020) 335\u2013345.","DOI":"10.1109\/TMI.2020.3026261"},{"key":"e_1_3_2_108_2","volume-title":"International Conference on Learning Representations (ICLR\u201917)","author":"Liu Yanpei","year":"2017","unstructured":"Yanpei Liu, Xinyun Chen, Chang Liu, and Dawn Song. 2017. Delving into transferable adversarial examples and black-box attacks. In International Conference on Learning Representations (ICLR\u201917)."},{"key":"e_1_3_2_109_2","article-title":"Robustifying deep networks for image segmentation","author":"Liu Zheng","year":"2019","unstructured":"Zheng Liu, Jinnian Zhang, Varun Jog, Po-Ling Loh, and Alan B. McMillan. 2019. Robustifying deep networks for image segmentation. arXiv preprint arXiv:1908.00656 (2019).","journal-title":"arXiv preprint arXiv:1908.00656"},{"key":"e_1_3_2_110_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10278-021-00507-5"},{"key":"e_1_3_2_111_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00102"},{"key":"e_1_3_2_112_2","first-page":"19288","article-title":"Finding optimal tangent points for reducing distortions of hard-label attacks","volume":"34","author":"Ma Chen","year":"2021","unstructured":"Chen Ma, Xiangyu Guo, Li Chen, Jun-Hai Yong, and Yisen Wang. 2021. Finding optimal tangent points for reducing distortions of hard-label attacks. Advan. Neural Inf. Process. Syst. 34 (2021), 19288\u201319300.","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_2_113_2","article-title":"Increasing-margin adversarial (IMA) training to improve adversarial robustness of neural networks","author":"Ma Linhai","year":"2020","unstructured":"Linhai Ma and Liang Liang. 2020. Increasing-margin adversarial (IMA) training to improve adversarial robustness of neural networks. arXiv preprint arXiv:2005.09147 (2020).","journal-title":"arXiv preprint arXiv:2005.09147"},{"key":"e_1_3_2_114_2","article-title":"Adaptive adversarial training to improve adversarial robustness of DNNs for medical image segmentation and detection","author":"Ma Linhai","year":"2022","unstructured":"Linhai Ma and Liang Liang. 2022. Adaptive adversarial training to improve adversarial robustness of DNNs for medical image segmentation and detection. arXiv preprint arXiv:2206.01736 (2022).","journal-title":"arXiv preprint arXiv:2206.01736"},{"key":"e_1_3_2_115_2","doi-asserted-by":"crossref","unstructured":"Xingjun Ma Yuhao Niu Lin Gu Yisen Wang Yitian Zhao James Bailey and Feng Lu. 2021. Understanding adversarial attacks on deep learning based medical image analysis systems. Pattern Recognition 110 (2021) 107332.","DOI":"10.1016\/j.patcog.2020.107332"},{"key":"e_1_3_2_116_2","volume-title":"International Conference on Learning Representations (ICLR\u201918)","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In International Conference on Learning Representations (ICLR\u201918)."},{"key":"e_1_3_2_117_2","doi-asserted-by":"crossref","unstructured":"Theodore V. Maliamanis Kyriakos D. Apostolidis and George A. Papakostas. 2022. How resilient are deep learning models in medical image analysis? The case of the moment-based adversarial attack (Mb-AdA). Biomedicines 10 10 (2022) 2545.","DOI":"10.3390\/biomedicines10102545"},{"key":"e_1_3_2_118_2","volume-title":"11th International Conference on Learning Representations (ICLR\u201923)","author":"Mao Chengzhi","year":"2023","unstructured":"Chengzhi Mao, Scott Geng, Junfeng Yang, Xin Wang, and Carl Vondrick. 2023. Understanding zero-shot adversarial robustness for large-scale models. In 11th International Conference on Learning Representations (ICLR\u201923)."},{"key":"e_1_3_2_119_2","doi-asserted-by":"crossref","unstructured":"Akinori Minagi Hokuto Hirano and Kauzhiro Takemoto. 2022. Natural images allow universal adversarial attacks on medical image classification using deep neural networks with transfer learning. Journal of Imaging 8 2 (2022) 38.","DOI":"10.3390\/jimaging8020038"},{"key":"e_1_3_2_120_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.17"},{"key":"e_1_3_2_121_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.282"},{"key":"e_1_3_2_122_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17247-2_3"},{"key":"e_1_3_2_123_2","first-page":"543","article-title":"A method for solving the convex programming problem with convergence rate  \\(O(1\/k^2)\\)","volume":"269","author":"Nesterov Yurii","year":"1983","unstructured":"Yurii Nesterov. 1983. A method for solving the convex programming problem with convergence rate \\(O(1\/k^2)\\) . Proc. USSR Acad. Sci. 269 (1983), 543\u2013547.","journal-title":"Proc. USSR Acad. Sci."},{"key":"e_1_3_2_124_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.swevo.2012.05.001"},{"key":"e_1_3_2_125_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32245-8_34"},{"key":"e_1_3_2_126_2","doi-asserted-by":"publisher","DOI":"10.3390\/app11094233"},{"key":"e_1_3_2_127_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-16452-1_8"},{"key":"e_1_3_2_128_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"e_1_3_2_129_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59354-4_5"},{"key":"e_1_3_2_130_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00928-1_56"},{"key":"e_1_3_2_131_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIPTM54933.2022.9754100"},{"key":"e_1_3_2_132_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI45749.2020.9098740"},{"key":"e_1_3_2_133_2","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2016.2538465"},{"key":"e_1_3_2_134_2","unstructured":"Mst. Tasnim Pervin Linmi Tao Aminul Huq Zuoxiang He and Li Huo. 2021. Adversarial attack driven data augmentation for accurate and robust medical image segmentation. Retrieved from https:\/\/arxiv.org\/abs\/2105.12106"},{"key":"e_1_3_2_135_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2019.100199"},{"key":"e_1_3_2_136_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00465"},{"key":"e_1_3_2_137_2","volume-title":"International Conference on Learning Representations (ICLR\u201921)","author":"Qi Gege","year":"2021","unstructured":"Gege Qi, Lijun Gong, Yibing Song, Kai Ma, and Yefeng Zheng. 2021. Stabilized medical image attacks. In International Conference on Learning Representations (ICLR\u201921)."},{"key":"e_1_3_2_138_2","volume-title":"International Conference on Learning Representations (ICLR\u201923)","author":"Rade Rahul","year":"2022","unstructured":"Rahul Rade and Seyed-Mohsen Moosavi-Dezfooli. 2022. Reducing excessive margin to achieve a better accuracy vs. robustness trade-off. In International Conference on Learning Representations (ICLR\u201923)."},{"key":"e_1_3_2_139_2","doi-asserted-by":"publisher","unstructured":"Abdur Rahman M. Shamim Hossain Nabil A. Alrajeh and Fawaz Alsolami. 2021. Adversarial examples\u2014security threats to COVID-19 deep learning systems in medical IoT devices. IEEE Internet of Things Journal 8 12 (2021) 9603\u20139610. DOI:10.1109\/JIOT.2020.3013710","DOI":"10.1109\/JIOT.2020.3013710"},{"key":"e_1_3_2_140_2","volume-title":"International Conference on Machine Learning (ICML\u201920)","author":"Raj Ankit","year":"2020","unstructured":"Ankit Raj, Yoram Bresler, and Bo Li. 2020. Improving robustness of deep-learning-based image reconstruction. In International Conference on Machine Learning (ICML\u201920)."},{"key":"e_1_3_2_141_2","article-title":"A thorough comparison study on adversarial attacks and defenses for common thorax disease classification in chest x-rays","author":"Rao Chendi","year":"2020","unstructured":"Chendi Rao, Jiezhang Cao, Runhao Zeng, Qi Chen, Huazhu Fu, Yanwu Xu, and Mingkui Tan. 2020. A thorough comparison study on adversarial attacks and defenses for common thorax disease classification in chest x-rays. arXiv preprint arXiv:2003.13969 (2020).","journal-title":"arXiv preprint arXiv:2003.13969"},{"key":"e_1_3_2_142_2","doi-asserted-by":"publisher","DOI":"10.1109\/IUS52206.2021.9593490"},{"key":"e_1_3_2_143_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32692-0_1"},{"key":"e_1_3_2_144_2","doi-asserted-by":"publisher","DOI":"10.1186\/s12911-022-01891-w"},{"key":"e_1_3_2_145_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICISCAE55891.2022.9927611"},{"key":"e_1_3_2_146_2","doi-asserted-by":"crossref","unstructured":"Olaf Ronneberger Philipp Fischer and Thomas Brox. 2015. U-net: Convolutional networks for biomedical image segmentation. In Medical Image Computing and Computer-Assisted Intervention\u2013MICCAI 2015: 18th International Conference Munich Germany October 5-9 2015 Proceedings Part III 18 Springer 234\u2013241.","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"e_1_3_2_147_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_148_2","article-title":"Robust clip: Unsupervised adversarial fine-tuning of vision embeddings for robust large vision-language models","author":"Schlarmann Christian","year":"2024","unstructured":"Christian Schlarmann, Naman Deep Singh, Francesco Croce, and Matthias Hein. 2024. Robust clip: Unsupervised adversarial fine-tuning of vision embeddings for robust large vision-language models. arXiv preprint arXiv:2402.12336 (2024).","journal-title":"arXiv preprint arXiv:2402.12336"},{"key":"e_1_3_2_149_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-98886-9_21"},{"key":"e_1_3_2_150_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"e_1_3_2_151_2","article-title":"Adversarial training for free! In","author":"Shafahi Ali","year":"2019","unstructured":"Ali Shafahi, Mahyar Najibi, Mohammad Amin Ghiasi, Zheng Xu, John Dickerson, Christoph Studer, Larry S. Davis, Gavin Taylor, and Tom Goldstein. 2019. Adversarial training for free! In Annual Conference on Neural Information Processing Systems (NeurIPS\u201919).","journal-title":"Annual Conference on Neural Information Processing Systems (NeurIPS\u201919)"},{"key":"e_1_3_2_152_2","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI.2018.8363846"},{"key":"e_1_3_2_153_2","doi-asserted-by":"crossref","unstructured":"Samaneh Shamshiri and Insoo Sohn. 2022. Security methods for AI based COVID-19 analysis system: A survey. ICT Express 8 4 (2022) 555\u2013562.","DOI":"10.1016\/j.icte.2022.03.002"},{"key":"e_1_3_2_154_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.12.013"},{"key":"e_1_3_2_155_2","doi-asserted-by":"publisher","DOI":"10.1088\/1361-6560\/abc812"},{"key":"e_1_3_2_156_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2022.108923"},{"key":"e_1_3_2_157_2","doi-asserted-by":"publisher","DOI":"10.11610\/isij.4615"},{"key":"e_1_3_2_158_2","doi-asserted-by":"publisher","DOI":"10.1117\/12.2520589"},{"key":"e_1_3_2_159_2","article-title":"Multi-modal deep guided filtering for comprehensible medical image processing","author":"Stimpel Bernhard","year":"2019","unstructured":"Bernhard Stimpel, Christopher Syben, Franziska Schirrmacher, Philip Hoelter, Arnd D\u00f6rfler, and Andreas Maier. 2019. Multi-modal deep guided filtering for comprehensible medical image processing. IEEE Trans Med. Imag. (2019).","journal-title":"IEEE Trans Med. Imag."},{"key":"e_1_3_2_160_2","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"e_1_3_2_161_2","first-page":"33100","volume-title":"International Conference on Machine Learning (ICML\u201923)","author":"Sun Jiachen","year":"2023","unstructured":"Jiachen Sun, Jiongxiao Wang, Weili Nie, Zhiding Yu, Zhuoqing Mao, and Chaowei Xiao. 2023. A critical revisit of adversarial robustness in 3D point cloud recognition with diffusion-driven purification. In International Conference on Machine Learning (ICML\u201923). 33100\u201333114."},{"key":"e_1_3_2_162_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-16440-8_39"},{"key":"e_1_3_2_163_2","volume-title":"International Conference on Learning Representations (ICLR\u201914)","author":"Szegedy Christian","year":"2014","unstructured":"Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian J. Goodfellow, and Rob Fergus. 2014. Intriguing properties of neural networks. In International Conference on Learning Representations (ICLR\u201914)."},{"key":"e_1_3_2_164_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.01160"},{"key":"e_1_3_2_165_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i3.16371"},{"key":"e_1_3_2_166_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICME51207.2021.9428437"},{"key":"e_1_3_2_167_2","doi-asserted-by":"crossref","unstructured":"Ekin Tiu Ellie Talius Pujan Patel Curtis P. Langlotz Andrew Y. Ng and Pranav Rajpurkar. 2022. Expert-level detection of pathologies from unannotated chest X-ray images via self-supervised learning. Nature Biomedical Engineering 6 12 (2022) 1399\u20131406.","DOI":"10.1038\/s41551-022-00936-9"},{"key":"e_1_3_2_168_2","first-page":"1633","article-title":"On adaptive attacks to adversarial example defenses","volume":"33","author":"Tramer Florian","year":"2020","unstructured":"Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. 2020. On adaptive attacks to adversarial example defenses. Advan. Neural Inf. Process. Syst. 33 (2020), 1633\u20131645.","journal-title":"Advan. Neural Inf. Process. Syst."},{"key":"e_1_3_2_169_2","article-title":"Fuzzy unique image transformation: Defense against adversarial attacks on deep COVID-19 models","author":"Tripathi Achyut Mani","year":"2020","unstructured":"Achyut Mani Tripathi and Ashish Mishra. 2020. Fuzzy unique image transformation: Defense against adversarial attacks on deep COVID-19 models. arXiv preprint arXiv:2009.04004 (2020).","journal-title":"arXiv preprint arXiv:2009.04004"},{"key":"e_1_3_2_170_2","doi-asserted-by":"crossref","unstructured":"Min-Jen Tsai Ping-Yi Lin and Ming-En Lee. 2023. Adversarial attacks on medical image classification. Cancers 15 17 (2023) 4228.","DOI":"10.3390\/cancers15174228"},{"key":"e_1_3_2_171_2","first-page":"5025","volume-title":"International Conference on Machine Learning","author":"Uesato Jonathan","year":"2018","unstructured":"Jonathan Uesato, Brendan O\u2019Donoghue, Pushmeet Kohli, and Aaron Oord. 2018. Adversarial risk and the dangers of evaluating against weak attacks. In International Conference on Machine Learning. PMLR, 5025\u20135034."},{"key":"e_1_3_2_172_2","volume-title":"International Conference on Machine Learning Workshop (ICML Workshop\u201921)","author":"Uwimana Anisie","year":"2021","unstructured":"Anisie Uwimana and Ransalu Senanayake. 2021. Out of distribution detection and adversarial attacks on deep neural networks for robust medical image analysis. In International Conference on Machine Learning Workshop (ICML Workshop\u201921)."},{"key":"e_1_3_2_173_2","doi-asserted-by":"publisher","DOI":"10.23919\/FRUCT.2019.8711974"},{"key":"e_1_3_2_174_2","article-title":"Fourteen years of manifestations and factors of health insurance fraud, 2006\u20132020: A scoping review","volume":"9","author":"Villegas-Ortega Jos\u00e9","year":"2021","unstructured":"Jos\u00e9 Villegas-Ortega, Luciana Bellido-Boza, and David Mauricio. 2021. Fourteen years of manifestations and factors of health insurance fraud, 2006\u20132020: A scoping review. Health Just. 9 (2021).","journal-title":"Health Just."},{"key":"e_1_3_2_175_2","first-page":"73","volume-title":"Asian-Pacific Conference on Medical and Biological Engineering","author":"Wang Jian","year":"2023","unstructured":"Jian Wang, Sainan Zhang, Yanting Xie, Hongen Liao, and Fang Chen. 2023. Adversarial detection and defense for medical ultrasound images: From a frequency perspective. In Asian-Pacific Conference on Medical and Biological Engineering. Springer, 73\u201382."},{"key":"e_1_3_2_176_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02313"},{"issue":"4","key":"e_1_3_2_177_2","article-title":"AT-GAN: A generative attack model for adversarial transferring on generative adversarial nets","volume":"3","author":"Wang Xiaosen","year":"2019","unstructured":"Xiaosen Wang, Kun He, and John E. Hopcroft. 2019. AT-GAN: A generative attack model for adversarial transferring on generative adversarial nets. arXiv preprint arXiv:1904.07793 3, 4 (2019).","journal-title":"arXiv preprint arXiv:1904.07793"},{"key":"e_1_3_2_178_2","first-page":"678","volume-title":"International Conference on Natural Computation, Fuzzy Systems and Knowledge Discovery","author":"Wang Xiaoyin","year":"2021","unstructured":"Xiaoyin Wang, Shuo Lv, Jiaze Sun, and Shuyan Wang. 2021. Adversarial attacks medical diagnosis model with generative adversarial networks. In International Conference on Natural Computation, Fuzzy Systems and Knowledge Discovery. 678\u2013685."},{"key":"e_1_3_2_179_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.369"},{"key":"e_1_3_2_180_2","article-title":"Fight fire with fire: Reversing skin adversarial examples by multiscale diffusive and denoising aggregation mechanism","author":"Wang Yongwei","year":"2022","unstructured":"Yongwei Wang, Yuan Li, and Zhiqi Shen. 2022. Fight fire with fire: Reversing skin adversarial examples by multiscale diffusive and denoising aggregation mechanism. arXiv preprint arXiv:2208.10373 (2022).","journal-title":"arXiv preprint arXiv:2208.10373"},{"key":"e_1_3_2_181_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.compbiomed.2023.107310"},{"key":"e_1_3_2_182_2","volume-title":"International Conference on Learning Representations (ICLR\u201919)","author":"Wang Yisen","year":"2019","unstructured":"Yisen Wang, Difan Zou, Jinfeng Yi, James Bailey, Xingjun Ma, and Quanquan Gu. 2019. Improving adversarial robustness requires revisiting misclassified examples. In International Conference on Learning Representations (ICLR\u201919)."},{"key":"e_1_3_2_183_2","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2020.2982166"},{"key":"e_1_3_2_184_2","doi-asserted-by":"crossref","unstructured":"Zizhou Wang Xin Shu Yan Wang Yangqin Feng Lei Zhang and Zhang Yi. 2022. A feature space-restricted attention attack on medical deep learning systems. IEEE Transactions on Cybernetics 53 8 (2022) 5323\u20135335.","DOI":"10.1109\/TCYB.2022.3209175"},{"key":"e_1_3_2_185_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412560"},{"key":"e_1_3_2_186_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICIPMC55686.2022.00022"},{"key":"e_1_3_2_187_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/134"},{"key":"e_1_3_2_188_2","doi-asserted-by":"publisher","DOI":"10.1088\/1757-899X\/806\/1\/012050"},{"key":"e_1_3_2_189_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i3.25395"},{"key":"e_1_3_2_190_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2018\/543"},{"key":"e_1_3_2_191_2","volume-title":"International Conference on Learning Representations (ICLR\u201918)","author":"Xie Cihang","year":"2018","unstructured":"Cihang Xie, Jianyu Wang, Zhishuai Zhang, Zhou Ren, and Alan L. Yuille. 2018. Mitigating adversarial effects through randomization. In International Conference on Learning Representations (ICLR\u201918)."},{"key":"e_1_3_2_192_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.153"},{"key":"e_1_3_2_193_2","volume-title":"International Conference on Learning Representations (ICLR\u201920)","author":"Xie Cihang","year":"2020","unstructured":"Cihang Xie and Alan L. Yuille. 2020. Intriguing properties of adversarial training at scale. In International Conference on Learning Representations (ICLR\u201920)."},{"key":"e_1_3_2_194_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00284"},{"key":"e_1_3_2_195_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-12053-4_33"},{"key":"e_1_3_2_196_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2021.101977"},{"key":"e_1_3_2_197_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3183095"},{"key":"e_1_3_2_198_2","doi-asserted-by":"crossref","unstructured":"Mengting Xu Tao Zhang and Daoqiang Zhang. 2022. Medrdf: A robust and retrain-less diagnostic framework for medical pretrained models against adversarial attack. IEEE Transactions on Medical Imaging 41 8 (2022) 2130\u20132143.","DOI":"10.1109\/TMI.2022.3156268"},{"key":"e_1_3_2_199_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-32226-7_94"},{"key":"e_1_3_2_200_2","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001422540052"},{"key":"e_1_3_2_201_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59719-1_67"},{"key":"e_1_3_2_202_2","unstructured":"Qingsong Yao Zecheng He Yuexiang Li Yi Lin Kai Ma Yefeng Zheng and S. Kevin Zhou. 2023. Adversarial medical image with hierarchical feature hiding. IEEE Transactions on Medical Imaging (2023)."},{"key":"e_1_3_2_203_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-87199-4_4"},{"key":"e_1_3_2_204_2","article-title":"Medical aegis: Robust adversarial protectors for medical images","author":"Yao Qingsong","year":"2021","unstructured":"Qingsong Yao, Zecheng He, and S. Kevin Zhou. 2021. Medical aegis: Robust adversarial protectors for medical images. arXiv preprint:2111.10969 (2021).","journal-title":"arXiv preprint:2111.10969"},{"key":"e_1_3_2_205_2","doi-asserted-by":"crossref","unstructured":"P.-T. Yap Raveendran Paramesran and Seng-Huat Ong. 2003. Image analysis by Krawtchouk moments. IEEE Transactions on Image Processing 12 11 (2003) 1367\u20131377.","DOI":"10.1109\/TIP.2003.818019"},{"key":"e_1_3_2_206_2","unstructured":"Maksym Yatsura Jan Metzen and Matthias Hein. 2021. Meta-learning the search distribution of black-box random search based adversarial attacks. Advances in Neural Information Processing Systems 34 (2021) 30181\u201330195."},{"key":"e_1_3_2_207_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-79457-6_44"},{"key":"e_1_3_2_208_2","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/173"},{"key":"e_1_3_2_209_2","doi-asserted-by":"publisher","DOI":"10.1001\/jamaophthalmol.2020.3442"},{"key":"e_1_3_2_210_2","first-page":"12062","volume-title":"International Conference on Machine Learning (ICML\u201921)","author":"Yoon Jongmin","year":"2021","unstructured":"Jongmin Yoon, Sung Ju Hwang, and Juho Lee. 2021. Adversarial purification with score-based generative models. In International Conference on Machine Learning (ICML\u201921). PMLR, 12062\u201312072."},{"key":"e_1_3_2_211_2","first-page":"25595","volume-title":"International Conference on Machine Learning (ICML\u201922)","author":"Yu Chaojian","year":"2022","unstructured":"Chaojian Yu, Bo Han, Li Shen, Jun Yu, Chen Gong, Mingming Gong, and Tongliang Liu. 2022. Understanding robust overfitting of adversarial training and beyond. In International Conference on Machine Learning (ICML\u201922). PMLR, 25595\u201325610."},{"key":"e_1_3_2_212_2","doi-asserted-by":"crossref","unstructured":"Sheikh Burhan Ul Haque and Aasim Zafar. 2024. Robust medical diagnosis: A novel two-phase deep learning framework for adversarial proof disease detection in radiology images. Journal of Imaging Informatics in Medicine 37 1 (2024) 308\u2013338.","DOI":"10.1007\/s10278-023-00916-8"},{"key":"e_1_3_2_213_2","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"e_1_3_2_214_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-022-31560-5"},{"key":"e_1_3_2_215_2","volume-title":"International Conference on Machine Learning","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019. Theoretically principled trade-off between robustness and accuracy. In International Conference on Machine Learning(ICML\u201919)."},{"key":"e_1_3_2_216_2","first-page":"11278","volume-title":"International Conference on Machine Learning (ICML\u201920)","author":"Zhang Jingfeng","year":"2020","unstructured":"Jingfeng Zhang, Xilie Xu, Bo Han, Gang Niu, Lizhen Cui, Masashi Sugiyama, and Mohan Kankanhalli. 2020. Attacks which do not kill training make adversarial learning stronger. In International Conference on Machine Learning (ICML\u201920). 11278\u201311287."},{"key":"e_1_3_2_217_2","volume-title":"International Conference on Learning Representations (ICLR\u201922)","author":"Zhang Yonggang","year":"2022","unstructured":"Yonggang Zhang, Mingming Gong, Tongliang Liu, Gang Niu, Xinmei Tian, Bo Han, Bernhard Sch\u00f6lkopf, and Kun Zhang. 2022. Adversarial robustness through the lens of causality. In International Conference on Learning Representations (ICLR\u201922)."},{"key":"e_1_3_2_218_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33012253"},{"key":"e_1_3_2_219_2","first-page":"42517","volume-title":"International Conference on Machine Learning (ICML\u201923)","author":"Zhou Dawei","year":"2023","unstructured":"Dawei Zhou, Yukun Chen, Nannan Wang, Decheng Liu, Xinbo Gao, and Tongliang Liu. 2023. Eliminating adversarial noise via information discard and robust representation restoration. In International Conference on Machine Learning (ICML\u201923). PMLR, 42517\u201342530."},{"key":"e_1_3_2_220_2","doi-asserted-by":"crossref","first-page":"12835","DOI":"10.1007\/978-981-15-1967-3","volume-title":"International Conference on Machine Learning (ICML\u201921)","author":"Zhou Dawei","year":"2021","unstructured":"Dawei Zhou, Tongliang Liu, Bo Han, Nannan Wang, Chunlei Peng, and Xinbo Gao. 2021. Towards defending against adversarial examples via attack-invariant features. In International Conference on Machine Learning (ICML\u201921). PMLR, 12835\u201312845."},{"key":"e_1_3_2_221_2","first-page":"27338","volume-title":"International Conference on Machine Learning (ICML\u201922)","author":"Zhou Dawei","year":"2022","unstructured":"Dawei Zhou, Nannan Wang, Xinbo Gao, Bo Han, Xiaoyu Wang, Yibing Zhan, and Tongliang Liu. 2022. Improving adversarial robustness via mutual information estimation. In International Conference on Machine Learning (ICML\u201922). PMLR, 27338\u201327352."},{"key":"e_1_3_2_222_2","first-page":"27353","volume-title":"International Conference on Machine Learning (ICML\u201922)","author":"Zhou Dawei","year":"2022","unstructured":"Dawei Zhou, Nannan Wang, Bo Han, and Tongliang Liu. 2022. Modeling adversarial noise for adversarial training. In International Conference on Machine Learning (ICML\u201922). PMLR, 27353\u201327366."},{"key":"e_1_3_2_223_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00778"},{"key":"e_1_3_2_224_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2021.102117"},{"key":"e_1_3_2_225_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-021-25548-w"},{"key":"e_1_3_2_226_2","volume-title":"International Conference on Learning Representations (ICLR\u201922)","author":"Zhu Jianing","year":"2022","unstructured":"Jianing Zhu, Jiangchao Yao, Bo Han, Jingfeng Zhang, Tongliang Liu, Gang Niu, Jingren Zhou, Jianliang Xu, and Hongxia Yang. 2022. Reliable adversarial distillation with unreliable teachers. In International Conference on Learning Representations (ICLR\u201922)."},{"key":"e_1_3_2_227_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01613"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3702638","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3702638","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:09Z","timestamp":1750295889000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3702638"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,22]]},"references-count":226,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,3,31]]}},"alternative-id":["10.1145\/3702638"],"URL":"https:\/\/doi.org\/10.1145\/3702638","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,22]]},"assertion":[{"value":"2024-04-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-10-19","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}