As interest in deep neural networks (DNNs) for image reconstruction tasks grows, their reliability has been called into question [V. Antun, F. Renna, C. Poon, B. Adcock, and A. C. Hansen, Proc. Natl. Acad. Sci. USA, 117 (2020), pp. 30088–30095; N. M. Gottschling, V. Antun, B. Adcock, and A. C. Hansen, The Troublesome Kernel: Why Deep Learning for Inverse Problems Is Typically Unstable, preprint, arXiv:2001.01258, 2020]. However, recent work has shown that, compared to total variation (TV) minimization, when appropriately regularized, DNNs show similar robustness to adversarial noise in terms of ℓ2 -reconstruction error [M. Genzel, J. Macdonald, and M. März, IEEE Trans. Pattern Anal., 45 (2022), pp. 1119–1134]. We consider a different notion of robustness, using the ℓ∞ -norm, and argue that localized reconstruction artifacts are a more relevant defect than the ℓ2 -error. We create adversarial perturbations to undersampled magnetic resonance imaging measurements (in the frequency domain) which induce severe localized artifacts in the TV-regularized reconstruction. Notably, the same attack method is not as effective against DNN-based reconstruction. Finally, we show that this phenomenon is inherent to reconstruction methods for which exact recovery can be guaranteed, as with compressed sensing reconstructions with ℓ1 - or TV-minimization.

Short Communication: Localized Adversarial Artifacts for Compressed Sensing MRI

Rima Alaifari;Giovanni S. Alberti;Tandri Gauksson
2023-01-01

Abstract

As interest in deep neural networks (DNNs) for image reconstruction tasks grows, their reliability has been called into question [V. Antun, F. Renna, C. Poon, B. Adcock, and A. C. Hansen, Proc. Natl. Acad. Sci. USA, 117 (2020), pp. 30088–30095; N. M. Gottschling, V. Antun, B. Adcock, and A. C. Hansen, The Troublesome Kernel: Why Deep Learning for Inverse Problems Is Typically Unstable, preprint, arXiv:2001.01258, 2020]. However, recent work has shown that, compared to total variation (TV) minimization, when appropriately regularized, DNNs show similar robustness to adversarial noise in terms of ℓ2 -reconstruction error [M. Genzel, J. Macdonald, and M. März, IEEE Trans. Pattern Anal., 45 (2022), pp. 1119–1134]. We consider a different notion of robustness, using the ℓ∞ -norm, and argue that localized reconstruction artifacts are a more relevant defect than the ℓ2 -error. We create adversarial perturbations to undersampled magnetic resonance imaging measurements (in the frequency domain) which induce severe localized artifacts in the TV-regularized reconstruction. Notably, the same attack method is not as effective against DNN-based reconstruction. Finally, we show that this phenomenon is inherent to reconstruction methods for which exact recovery can be guaranteed, as with compressed sensing reconstructions with ℓ1 - or TV-minimization.
File in questo prodotto:
File Dimensione Formato  
alaifari-et-al-2023-short-communication-localized-adversarial-artifacts-for-compressed-sensing-mri.pdf

accesso chiuso

Descrizione: Articolo
Tipologia: Documento in versione editoriale
Dimensione 2.14 MB
Formato Adobe PDF
2.14 MB Adobe PDF   Visualizza/Apri   Richiedi una copia

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1148116
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 3
  • ???jsp.display-item.citation.isi??? 3
social impact