Balancing Efficiency and Effectiveness: Adversarial Example Generation in Pneumonia Detection
Den Muhammad Hafiz Jumaatuden, M. A. B. Md Ali, Hafizah Noor Isa · 2024
Generative AI offers numerous benefits to society, but it also poses significant threats. One such threat is its potential to poison datasets with corrupted images, thereby reducing the accuracy of already deployed models. This paper presents a comparative study of such adversarial methods for generating adversarial examples in the domain of chest X-ray imaging for pneumonia detection. Adversarial examples will be generated for 624 test images out of 5,856 total images from the Guangzhou Women and Children's Medical Center Chest X-ray dataset. The methods tested include Fast Gradient Sign Method (FGSM), Basic Iterative Method (BIM), and DeepFool. No significant visual differences on adversarial examples produced by all methods. Our experiments reveal that FGSM is the most efficient, achieving a generation time of 8.4 seconds to generate 624 images. In contrast, DeepFool produces the most effective adversarial examples, as indicated by its superior performance with an F1-score of 0.31 and an L2 norm of 2.081. These findings highlight the trade-offs between computational efficiency and the quality of adversarial examples, providing valuable insights for selecting appropriate methods in medical image analysis and adversarial research.