Training-Free Adversarial Robustness in Computational MRI
Mahdi Saberi, Chi Zhang, Mehmet Akcakaya
Abstract
Deep learning (DL) methods have become the state-of-the-art for reconstructing sub-sampled magnetic resonance imaging (MRI) data. However, studies have shown that these methods are susceptible to small adversarial input perturbations, resulting in major distortions in the output images. Various strategies have been proposed to reduce the effects of these attacks, but they require retraining. In this work, we propose a novel approach for mitigating adversarial attacks on MRI reconstruction models without any retraining. Based on the idea of cyclic measurement consistency, we devise a novel mitigation objective that is minimized in a small ball around the attack input. Results show that our method substantially reduces the impact of adversarial perturbations across different datasets, attack types/strengths and PD-DL networks, and qualitatively and quantitatively outperforms conventional mitigation methods. We also introduce a practically relevant scenario for small adversarial perturbations that models impulse noise in raw data, which relates to herringbone artifacts, and show the applicability of our approach in this setting. Finally, we show our mitigation approach remains effective in two realistic extension scenarios: a blind setup, where the attack strength or algorithm is not known to the user; and an adaptive attack setup, where the attacker has full knowledge of the defense strategy. Code available at: https://github.com/MahdiSaberii/CycMit-MRI
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d8e0b9a4-07ec-4a11-a068-d01180bc0d4cBuilds on15
- On Adaptive Attacks to Adversarial Example DefensesFlorian Tramèr, Nicholas Carlini, Wieland Brendel, Aleksander MadryNeurIPS 2020 · 1,026 citations
- Diffusion Models for Adversarial PurificationWeili Nie, Brandon Guo, Yujia Huang, Chaowei Xiao et al.ICML 2022 · 663 citations
- Denoised Smoothing: A Provable Defense for Pretrained ClassifiersHadi Salman, Mingjie Sun, Greg Yang, Ashish Kapoor et al.NeurIPS 2020 · 191 citations
- Diffusion Posterior Sampling for General Noisy Inverse ProblemsHyungjin Chung, Jeongsol Kim, Michael Thompson McCann, Marc Louis Klasky et al.ICLR 2023 · 152 citations
- Zero-Shot Self-Supervised Learning for MRI ReconstructionBurhaneddin Yaman, Seyed Amir Hossein Hosseini, Mehmet AkçakayaICLR 2022 · 109 citations
Related papers
- Measuring Robustness in Deep Learning Based Compressive SensingMohammad Zalbagi Darestani, Akshay S. Chaudhari, Reinhard HeckelICML 2021 · 94 citations
- MRI Banding Removal via Adversarial TrainingAaron Defazio, Tullie Murrell, Michael P. RechtNeurIPS 2020 · 17 citations
- Improving Robustness of Deep-Learning-Based Image ReconstructionAnkit Raj, Yoram Bresler, Bo LiICML 2020 · 58 citations
- ResoNet: Noise-Trained Physics-Informed MRI Off-Resonance CorrectionAlfredo De Goyeneche Macaya, Shreya Ramachandran, Ke Wang, Ekin Karasan et al.NeurIPS 2023 · 4 citations
- A Unified Model for Compressed Sensing MRI Across Undersampling PatternsArmeet Singh Jatyani, Jiayun Wang, Aditi Chandrashekar, Zihui Wu et al.CVPR 2025
