Effects on Selective Removal of Adversarial Examples for Noisy X-ray Images
Haruto Namura, Tatsuki Itasaka, Masahiro Okuda · 2023
Preprocessing the input images of the deep neural networks (DNN) is a way to prevent adversarial attacks without compromising the classification performance of the targeted model. Especially, considering the perturbation as noise, then applying denoising as the preprocessing method is known to be effective in removing perturbations caused by adversarial attacks. However, perturbation removal can result in excessive image smoothing and finer details of the image can be lost in the denoising process. Here, we experimentally confirm the effectiveness of selectively removing perturbations to maintain image quality after perturbation removal and propose an image reconstructing model based on Res-Unet.