As interest in deep neural networks (DNNs) for image reconstruction tasks grows, their reliability has been called into question [V. Antun, F. Renna, C. Poon, B. Adcock, and A. C. Hansen, Proc. Natl. Acad. Sci. USA, 117 (2020), pp. 30088–30095; N. M. Gottschling, V. Antun, B. Adcock, and A. C. Hansen, The Troublesome Kernel: Why Deep Learning for Inverse Problems Is Typically Unstable, preprint, arXiv:2001.01258, 2020]. However, recent work has shown that, compared to total variation (TV) minimization, when appropriately regularized, DNNs show similar robustness to adversarial noise in terms of ℓ2 -reconstruction error [M. Genzel, J. Macdonald, and M. März, IEEE Trans. Pattern Anal., 45 (2022), pp. 1119–1134]. We consider a different notion of robustness, using the ℓ∞ -norm, and argue that localized reconstruction artifacts are a more relevant defect than the ℓ2 -error. We create adversarial perturbations to undersampled magnetic resonance imaging measurements (in the frequency domain) which induce severe localized artifacts in the TV-regularized reconstruction. Notably, the same attack method is not as effective against DNN-based reconstruction. Finally, we show that this phenomenon is inherent to reconstruction methods for which exact recovery can be guaranteed, as with compressed sensing reconstructions with ℓ1 - or TV-minimization.
Short Communication: Localized Adversarial Artifacts for Compressed Sensing MRI
Rima Alaifari;Giovanni S. Alberti;Tandri Gauksson
2023-01-01
Abstract
As interest in deep neural networks (DNNs) for image reconstruction tasks grows, their reliability has been called into question [V. Antun, F. Renna, C. Poon, B. Adcock, and A. C. Hansen, Proc. Natl. Acad. Sci. USA, 117 (2020), pp. 30088–30095; N. M. Gottschling, V. Antun, B. Adcock, and A. C. Hansen, The Troublesome Kernel: Why Deep Learning for Inverse Problems Is Typically Unstable, preprint, arXiv:2001.01258, 2020]. However, recent work has shown that, compared to total variation (TV) minimization, when appropriately regularized, DNNs show similar robustness to adversarial noise in terms of ℓ2 -reconstruction error [M. Genzel, J. Macdonald, and M. März, IEEE Trans. Pattern Anal., 45 (2022), pp. 1119–1134]. We consider a different notion of robustness, using the ℓ∞ -norm, and argue that localized reconstruction artifacts are a more relevant defect than the ℓ2 -error. We create adversarial perturbations to undersampled magnetic resonance imaging measurements (in the frequency domain) which induce severe localized artifacts in the TV-regularized reconstruction. Notably, the same attack method is not as effective against DNN-based reconstruction. Finally, we show that this phenomenon is inherent to reconstruction methods for which exact recovery can be guaranteed, as with compressed sensing reconstructions with ℓ1 - or TV-minimization.| File | Dimensione | Formato | |
|---|---|---|---|
|
alaifari-et-al-2023-short-communication-localized-adversarial-artifacts-for-compressed-sensing-mri.pdf
accesso chiuso
Descrizione: Articolo
Tipologia:
Documento in versione editoriale
Dimensione
2.14 MB
Formato
Adobe PDF
|
2.14 MB | Adobe PDF | Visualizza/Apri Richiedi una copia |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



