Improving Robustness of Deep-Learning-Based Image Reconstruction
Ankit Raj, Yoram Bresler, Bo Li
Abstract
Deep-learning-based methods for different applications have been shown vulnerable to adversarial examples. These examples make deployment of such models in safety-critical tasks questionable. Use of deep neural networks as inverse problem solvers has generated much excitement for medical imaging including CT and MRI, but recently a similar vulnerability has also been demonstrated for these tasks. We show that for such inverse problem solvers, one should analyze and study the effect of adversaries in the measurement-space, instead of the signal-space as in previous work. In this paper, we propose to modify the training strategy of end-to-end deep-learning-based inverse problem solvers to improve robustness. We introduce an auxiliary network to generate adversarial examples, which is used in a min-max formulation to build robust image reconstruction networks. Theoretically, we show for a linear reconstruction scheme the min-max formulation results in a singular-value(s) filter regularized solution, which suppresses the effect of adversarial examples occurring because of ill-conditioning in the measurement matrix. We find that a linear network using the proposed min-max learning scheme indeed converges to the same solution. In addition, for non-linear Compressed Sensing (CS) reconstruction using deep networks, we show significant improvement in robustness using the proposed approach over other methods. We complement the theory by experiments for CS on two different datasets and evaluate the effect of increasing perturbations on trained networks. We find the behavior for ill-conditioned and well-conditioned measurement matrices to be qualitatively different.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2b0b5255-7e2c-40af-baec-8407f7845428Cited by top-tier papers7
- How to Robustify Black-Box ML Models? A Zeroth-Order Optimization PerspectiveYimeng Zhang, Yuguang Yao, Jinghan Jia, Jinfeng Yi et al.ICLR 2022 · 41 citations
- Center Smoothing: Certified Robustness for Networks with Structured OutputsAounon Kumar, Tom GoldsteinNeurIPS 2021 · 23 citations
- Reasons for the Superiority of Stochastic Estimators over Deterministic Ones: Robustness, Consistency and Perceptual QualityGuy Ohayon, Theo Joseph Adrai, Michael Elad, Tomer MichaeliICML 2023 · 18 citations
- Learning Provably Robust Estimators for Inverse Problems via JitteringAnselm Krainovic, Mahdi Soltanolkotabi, Reinhard HeckelNeurIPS 2023 · 10 citations
- How many measurements are enough? Bayesian recovery in inverse problems with general distributionsBen Adcock, Zi Yuan (Nick) HuangNeurIPS 2025 · 2 citations
Builds on4
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural NetworksWeilin Xu, David Evans, Yanjun QiNDSS 2018 · 1,633 citations
- Adversarial Defense via Learning to Generate Diverse AttacksYunseok Jang, Tianchen Zhao, Seunghoon Hong, Honglak LeeICCV 2019 · 88 citations
- Evaluating Robustness of Deep Image Super-Resolution Against Adversarial AttacksJun-Ho Choi, Huan Zhang, Jun-Hyuk Kim, Cho-Jui Hsieh et al.ICCV 2019 · 82 citations
- GAN-Based Projector for Faster Recovery With Convergence Guarantees in Linear Inverse ProblemsAnkit Raj, Yuqi Li, Yoram BreslerICCV 2019 · 61 citations
Related papers
- Measuring Robustness in Deep Learning Based Compressive SensingMohammad Zalbagi Darestani, Akshay S. Chaudhari, Reinhard HeckelICML 2021 · 94 citations
- NPN: Non-Linear Projections of the Null-Space for Imaging Inverse ProblemsRoman Jacome, Romario Gualdrón-Hurtado, León Suárez-Rodríguez, Henry ArguelloNeurIPS 2025 · 4 citations
- Training-Free Adversarial Robustness in Computational MRIMahdi Saberi, Chi Zhang, Mehmet AkcakayaICML 2026 · 2 citations
- Convex Regularization behind Neural ReconstructionArda Sahiner, Morteza Mardani, Batu Ozturkler, Mert Pilanci et al.ICLR 2021 · 25 citations
- Equivariant Imaging: Learning Beyond the Range SpaceDongdong Chen, Julián Tachella, Mike E. DaviesICCV 2021 · 139 citations
