Text-Guided Diffusion-Based Adversarial Attacks on Chest X-Ray Images

📅 2026-08-29
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出了一种基于文本引导的扩散生成对抗框架,用于在胸部X光图像上产生对抗样本,以测试多疾病分类器的鲁棒性,并揭示了人类与机器解释之间的临床重要差异。
📝 Abstract
As artificial intelligence is increasingly integrated into chest X-ray (CXR) interpretation, triage, and clinical decision support, understanding its vulnerability to adversarial manipulation is critical for safe deployment. Existing robustness evaluations, however, predominantly rely on pixel-space attacks that introduce numerically constrained perturbations but may not represent plausible radiographic variation. This limitation is particularly important in multi-disease CXR classification, where models simultaneously evaluate multiple overlapping pathologies and adversarial failures may alter several diagnostic predictions. We propose a text-guided diffusion-based adversarial framework that optimizes learnable text conditioning while keeping the diffusion generator and target classifier frozen, enabling adversarial generation through a learned image prior rather than direct pixel manipulation. We evaluate the framework across multiple classifier architectures in both binary atelectasis and multi-disease CXR classification and compare it with FGSM, PGD, and Carlini-Wagner attacks. Our approach consistently produced the greatest degradation in classifier performance, reducing AUROC to 0.3885-0.5646 in binary classification and 0.4441-0.4878 in the multi-disease setting, while achieving superior image fidelity (SSIM 0.9080, LPIPS 0.1670, FID 51.23). Importantly, clinician interpretation remained unchanged for 95.9% of binary and 73.8% of multi-disease adversarial images despite substantial changes in model predictions. These findings reveal a clinically important discrepancy between human and machine interpretation and demonstrate the need to extend medical AI robustness evaluation beyond conventional pixel-space attacks toward generative threat models that can expose failures under visually and clinically plausible image variations.
Problem

Research questions and friction points this paper is trying to address.

adversarial attacks
chest X-ray
artificial intelligence
robustness evaluation
multi-disease classification
Innovation

Methods, ideas, or system contributions that make the work stand out.

text-guided
diffusion-based
adversarial attacks
chest X-ray images
learnable text conditioning
🔎 Similar Papers
No similar papers found.
Basudha Pal
Basudha Pal
Doctoral Student, Johns Hopkins University
Deep learningComputer VisionHealthcare AI
A
Arjun Narayanan
Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal, 576104, Karnataka, India
N
Neha Ajith
Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal, 576104, Karnataka, India
V
Vikas R Bhat
Manipal Institute of Technology, Manipal Academy of Higher Education, Manipal, 576104, Karnataka, India
Muhammad Umair
Muhammad Umair
The Russell H. Morgan Department of Radiology and Radiological Science. The Johns Hopkins Hospital
Cardiovascular Imaging