Invention Grant
- Patent Title: Mitigating adversarial attacks on medical imaging understanding systems
-
Application No.: US17099372Application Date: 2020-11-16
-
Publication No.: US11763450B1Publication Date: 2023-09-19
- Inventor: Rahul Paul , Dmitry Goldgof , Lawrence Hall , Matthew Schabath , Robert Gillies
- Applicant: University of South Florida , H. LEE MOFFITT CANCER CENTER AND RESEARCH INSTITUTE, INC.
- Applicant Address: US FL Tampa
- Assignee: UNIVERSITY OF SOUTH FLORIDA,H. LEE MOFFITT CANCER CENTER AND RESEARCH INSTITUTE, INC.
- Current Assignee: UNIVERSITY OF SOUTH FLORIDA,H. LEE MOFFITT CANCER CENTER AND RESEARCH INSTITUTE, INC.
- Current Assignee Address: US FL Tampa; US FL Tampa
- Agency: QUARLES & BRADY LLP
- Main IPC: G06T7/00
- IPC: G06T7/00 ; G06F16/55 ; G16H30/20 ; G06N3/08 ; G06F18/214 ; G06F18/25 ; G06F18/2415 ; G06N3/045

Abstract:
The present disclosure describes a multi-initialization ensemble-based defense strategy against an adversarial attack. In one embodiment, an exemplary method includes training a plurality of conventional neural networks (CNNs) with a training set of images, wherein the images include original images and images modified by an adversarial attack; after training of the plurality of conventional neural networks, providing an input image to the plurality of conventional neural networks, wherein the input image has been modified by an adversarial attack; receiving a probability output for the input image from each of the plurality of conventional neural networks; producing an ensemble probability output for the input image by combining the probability outputs from each of the plurality of conventional neural networks; and labeling the input image as belonging to one of the one or more categories based on the ensemble probability output.
Information query