IP Library Granted Patent US 11,763,450
Granted Patent B1
US 11,763,450 · App. 17/099,372 · Granted Sep 19, 2023

Mitigating adversarial attacks on medical imaging understanding systems

Inventors: Rahul Paul (Tampa, FL); Dmitry Goldgof (Lutz, FL); Lawrence Hall (Tampa, FL); Matthew Schabath (Tampa, FL); Robert Gillies (Tampa, FL)
Assignees: UNIVERSITY OF SOUTH FLORIDA; H. LEE MOFFITT CANCER CENTER AND RESEARCH INSTITUTE, INC.
G06T7/0012G06F16/55G06F18/214G06F18/2415G06F18/254G06N3/045G06N3/08G16H30/20G06T2200/04G06T2207/10081G06T2207/20076G06T2207/20081G06T2207/20084
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,763,450
App. No.
17/099,372
Granted
Sep 19, 2023
Kind
B1
Abstract

The present disclosure describes a multi-initialization ensemble-based defense strategy against an adversarial attack. In one embodiment, an exemplary method includes training a plurality of conventional neural networks (CNNs) with a training set of images, wherein the images include original images and images modified by an adversarial attack; after training of the plurality of conventional neural networks, providing an input image to the plurality of conventional neural networks, wherein the input image has been modified by an adversarial attack; receiving a probability output for the input image from each of the plurality of conventional neural networks; producing an ensemble probability output for the input image by combining the probability outputs from each of the plurality of conventional neural networks; and labeling the input image as belonging to one of the one or more categories based on the ensemble probability output.

Claims (32)

1. A method comprising: training a plurality of convolutional neural networks multiple times with different seed point initializations with a training set of images, wherein the images include original images and images modified by an adversarial attack; after training of the plurality of convolutional neural networks, providing an input image to the plurality of convolutional neural networks, wherein the input image has been modified by an adversarial attack; receiving a probability output for the input image from each of the plurality of convolutional neural networks, wherein the probability output comprises a probability that the image belongs to one or more categories; producing an ensemble probability output for the input image by combining the probability outputs from each of the plurality of convolutional neural networks; and labeling the input image as belonging to one of the one or more categories based on the ensemble probability output.

2. The method of claim 1 , wherein the plurality of convolutional neural networks include convolutional neural networks of different convolutional neural network architectures.

3. The method of claim 2 , wherein the plurality of convolutional neural networks further include a convolutional neural network at different seed point initializations.

4. The method of claim 1 , wherein the plurality of convolutional neural networks further include a convolutional neural network at different seed point initializations.

5. The method of claim 1 , wherein the ensemble probability output image is combined by averaging the probability outputs from each of the plurality of convolutional neural networks.

6. The method of claim 1 , wherein the input image and the training set of images comprise a computed tomography scan.

7. The method of claim 6 , wherein the one or more categories involve a cancer diagnosis for a subject of the computed tomography scan.

8. The method of claim 1 , wherein the input image and the training set of images comprise 2D images.

9. The method of claim 1 , wherein the input image and the training set of images comprises 3D images.

10. The method of claim 1 , wherein the adversarial attack is a Fast Gradient Signed Method (FGSM) adversarial attack.

11. The method of claim 1 , wherein the adversarial attack is a one pixel adversarial attack.

12. The method of claim 1 , wherein the images modified by an adversarial attack comprise average ensemble attack images.

13. The method of claim 1 , wherein the images modified by an adversarial attack comprise maximum value ensemble attack images.

14. A system comprising:

a processor:

a tangible, non-transitory memory configured to communicate with the processor, the tangible, non-transitory memory having instructions stored thereon that, in response to execution by the processor, cause the processor perform operations comprising:

training each of a plurality of convolutional neural networks multiple times with different seed point initializations with a training set of images, wherein the images include original images and images modified by an adversarial attack;

after training of the plurality of convolutional neural networks, providing an input image to the plurality of convolutional neural networks, wherein the input image has been modified by an adversarial attack;

receiving a probability output for the input image from each of the plurality of convolutional neural networks, wherein the probability output comprises a probability that the image belongs to one or more categories;

producing an ensemble probability output for the input image by combining the probability outputs from each of the plurality of convolutional neural networks; and

labeling the input image as belonging to one of the one or more categories based on the ensemble probability output.

15. The system of claim 14 , wherein the plurality of convolutional neural networks include convolutional neural networks of different convolutional neural network architectures.

16. The system of claim 15 , wherein the plurality of convolutional neural networks further include a convolutional neural network at the different seed point initializations.

17. The system of claim 14 , wherein the ensemble probability output image is combined by averaging the probability outputs from each of the plurality of convolutional neural networks.

18. The system of claim 14 , wherein the input image and the training set of images comprise a computed tomography scan.

19. A non-transitory, tangible computer readable storage medium having instructions stored thereon that in response to execution by a computing device, cause the computing device to perform operations comprising:

training each of a plurality of convolutional neural networks multiple times with different seed point initializations with a training set of images, wherein the images include original images and images modified by an adversarial attack;

after training of the plurality of convolutional neural networks, providing an input image to the plurality of convolutional neural networks, wherein the input image has been modified by an adversarial attack;

receiving a probability output for the input image from each of the plurality of convolutional neural networks, wherein the probability output comprises a probability that the image belongs to one or more categories;

producing an ensemble probability output for the input image by combining the probability outputs from each of the plurality of convolutional neural networks; and

labeling the input image as belonging to one of the one or more categories based on the ensemble probability output.

20. The computer readable storage medium of claim 19 , wherein the ensemble probability output image is combined by averaging the probability outputs from each of the plurality of convolutional neural networks.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2023
From: PAUL, RAHUL
To: UNIVERSITY OF SOUTH FLORIDA
Reel/Frame 064313/0356 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2023
From: PAUL, RAHUL; GOLDGOF, DMITRY; HALL, LAWRENCE
To: UNIVERSITY OF SOUTH FLORIDA
Reel/Frame 064313/0549 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 19, 2023
From: SCHABATH, MATTHEW
To: H. LEE MOFFITT CANCER CENTER AND RESEARCH INSTITUTE, INC.
Reel/Frame 064313/0771 →
CONFIRMATORY LICENSE Recorded Dec 15, 2020
From: UNIVERSITY OF SOUTH FLORIDA
To: NATIONAL INSTITUTES OF HEALTH (NIH), U.S. DEPT. OF HEALTH AND HUMAN SERVICES (DHHS), U.S. GOVERNMENT
Reel/Frame 054761/0165 →
Continuity (2)
Provisional Application 62991715 · Mar 19, 2020
Provisional Application 62935179 · Nov 14, 2019