{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-attacks-against-medical-deep","title":"Adversarial Attacks Against Medical Deep Learning Systems","arxiv_id":"1804.05296","date":"2018-04-15","proceeding":null,"authors":["Samuel G. Finlayson","Hyung Won Chung","Isaac S. Kohane","Andrew L. Beam"],"abstract":"The discovery of adversarial examples has raised concerns about the practical\ndeployment of deep learning systems. In this paper, we demonstrate that\nadversarial examples are capable of manipulating deep learning systems across\nthree clinical domains. For each of our representative medical deep learning\nclassifiers, both white and black box attacks were highly successful. Our\nmodels are representative of the current state of the art in medical computer\nvision and, in some cases, directly reflect architectures already seeing\ndeployment in real world clinical settings. In addition to the technical\ncontribution of our paper, we synthesize a large body of knowledge about the\nhealthcare system to argue that medicine may be uniquely susceptible to\nadversarial attacks, both in terms of monetary incentives and technical\nvulnerability. To this end, we outline the healthcare economy and the\nincentives it creates for fraud and provide concrete examples of how and why\nsuch attacks could be realistically carried out. We urge practitioners to be\naware of current vulnerabilities when deploying deep learning systems in\nclinical settings, and encourage the machine learning community to further\ninvestigate the domain-specific characteristics of medical learning systems.","url_abs":"http://arxiv.org/abs/1804.05296v3","url_pdf":"http://arxiv.org/pdf/1804.05296v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-attacks-against-medical-deep","repo_url":"https://github.com/sgfin/adversarial-medicine","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[{"task_slug":"deep-learning","task_name":"Deep Learning"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=1804.05296","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1804.05296"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/sgfin/adversarial-medicine","reach":null}],"summary":{"ran_fixture":1,"ran_draft_wrong":2,"unverified":4},"by_repo_kind":{"official":{"samples":7,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"484ed1833bc0eb76","entry":"load_data","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"train_models/train_model.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/train_models/train_model.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"DEP_MISSING","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"484ed1833bc0eb76"}},{"code_sha256_prefix":"7308858d214bf0d2","entry":"load_data","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"pgd_attacks/craft_attacks.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/pgd_attacks/craft_attacks.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"7308858d214bf0d2"}},{"code_sha256_prefix":"2e369fe32f07c987","entry":"mean_ci","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"pgd_attacks/craft_attacks.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/pgd_attacks/craft_attacks.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":true,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"2e369fe32f07c987"}},{"code_sha256_prefix":"826517c053cb6c3b","entry":"construct_model","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"train_models/train_model.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/train_models/train_model.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"826517c053cb6c3b"}},{"code_sha256_prefix":"a8c1efc6d0ca0501","entry":"deprocess_inception","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"pgd_attacks/craft_attacks.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/pgd_attacks/craft_attacks.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"a8c1efc6d0ca0501"}},{"code_sha256_prefix":"c4f8f1a53760ab2f","entry":"generateCallbacks","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"train_models/train_model.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/train_models/train_model.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"c4f8f1a53760ab2f"}},{"code_sha256_prefix":"ff598d2b0694857e","entry":"mean_ci","repo":"sgfin/adversarial-medicine","repo_kind":"official","path":"patch_attacks/execute_patch_attacks.py","file_url":"https://github.com/sgfin/adversarial-medicine/blob/HEAD/patch_attacks/execute_patch_attacks.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"ff598d2b0694857e"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}