A text-guided diffusion-based adversarial framework that optimizes learnable text conditioning while keeping the diffusion generator and target classifier frozen, enabling adversarial generation through a learned image prior rather than direct pixel manipulation is proposed.
Abstract
As artificial intelligence is increasingly integrated into chest X-ray (CXR) interpretation, triage, and clinical decision support, understanding its vulnerability to adversarial manipulation is critical for safe deployment. Existing robustness evaluations, however, predominantly rely on pixel-space attacks that introduce numerically constrained perturbations but may not represent plausible radiographic variation. This limitation is particularly important in multi-disease CXR classification, where models simultaneously evaluate multiple overlapping pathologies and adversarial failures may alter several diagnostic predictions. We propose a text-guided diffusion-based adversarial framework that optimizes learnable text conditioning while keeping the diffusion generator and target classifier frozen, enabling adversarial generation through a learned image prior rather than direct pixel manipulation. We evaluate the framework across multiple classifier architectures in both binary atelectasis and multi-disease CXR classification and compare it with FGSM, PGD, and Carlini-Wagner attacks. Our approach consistently produced the greatest degradation in classifier performance, reducing AUROC to 0.3885-0.5646 in binary classification and 0.4441-0.4878 in the multi-disease setting, while achieving superior image fidelity (SSIM 0.9080, LPIPS 0.1670, FID 51.23). Importantly, clinician interpretation remained unchanged for 95.9% of binary and 73.8% of multi-disease adversarial images despite substantial changes in model predictions. These findings reveal a clinically important discrepancy between human and machine interpretation and demonstrate the need to extend medical AI robustness evaluation beyond conventional pixel-space attacks toward generative threat models that can expose failures under visually and clinically plausible image variations.
While Chest X-ray (CXR) classification effectively aids respiratory disease assessment, existing models often suffer from data leakage—the presence of duplicate or near-duplicate images across training, validation, and test sets that can artificially inflate performance metrics—and poor interpretability by highlighting...
Ly Yen Nguyen-Thi, L. T. Tran, Thien B. Nguyen-Tat· International Conference on...· 0 citations
Prostate cancer is a highly prevalent malignancy, and deep learning has significantly advanced di agnostic models based on multi-parametric MRI (mpMRI). However, the robustness of these models is threatened by adversarial attacks, potentially leading to fatal misdiagnoses and impeding clinical translation. Unlike natur...
Yu Zhang, Jun-Qiang Qiu, Dong-Hui Li et al.· IEEE journal of biomedical a...· 0 citations
Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependen...
Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al.· IEEE Transactions on Image P...· 0 citations
Although AI models achieve impressive performance on chest X-ray benchmarks, their deployment in real-world clinical settings remains challenging due to performance degradation under unpredictable conditions. To understand how these AI models can adapt in practice, we systematically evaluate several Test-Time Adaptatio...
Duc-Ngo Van, Kim-Hung Le· International Conference on...· 0 citations
Abstract Artificial intelligence (AI) has become the most transformative development in radiology since digital imaging, with deep learning algorithms demonstrating validated—and in controlled settings superior—performance across pulmonary nodule detection, breast cancer screening, tuberculosis (TB) triage, acute strok...
Emily Das, Rasel Mondal, Ashim Dhor et al.· Indian Journal of Radiology...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.