A study of adversarial attacks on malaria cell image classification

Citation

M. T. Pervin and A. Huq, "A Study of Adversarial Attacks on Malaria Cell Image Classification," 2021 IEEE International Women in Engineering (WIE) Conference on Electrical and Computer Engineering (WIECON-ECE), Dhaka, Bangladesh, 2021, pp. 79-82, doi: 10.1109/WIECON-ECE54711.2021.9829560.

Abstract

In all mosquito borne diseases in the world no other disease is as dangerous Malaria. According to the WHO 409,000 people died of this disease in 2020. Early detection and diagnosis can aid in saving precious human lives. In order to identify Malaria infected cells properly, expertise is needed from people. Deep learning approaches can aid in such tasks since they can accurately identify these cell images in large-scale scenarios without any fatigue. In recent studies, it has been shown that, in spite of the success that deep learning has achieved in varying applications, it is unreliable. Adversarial perturbations when added to the input data forces the model to provide wrong answers. We used VGG16, ResNet18 and Wide-ResNet-28-10 model to correctly classify infected Malaria cells from normal images. We also performed Fast Gradient Sign Method (FGSM) attack to evaluate the robustness of these models. FGSM adversarial training was performed on these models to defend it from such attacks as well. We studied in depth the effects of this attack against these models by varying maximum allowed perturbations. We achieved 95.74%, 95.94% and 95.30% accuracy on clean data and 92.71%, 90.64%, and 88.73% accuracy on adversarial images after performing adversarial training for VGG16, ResNet and Wide-ResNet respectively.

Description

Type

Conference Proceeding