Next Article in Journal
Weak Calibration of a Visible Light Positioning System Based on a Position-Sensitive Detector: Positioning Error Assessment
Next Article in Special Issue
GMSRI: A Texture-Based Martian Surface Rock Image Dataset
Previous Article in Journal
Construction and Application of Graphene Oxide-Bovine Serum Albumin Modified Extended Gate Field Effect Transistor Chiral Sensor
Previous Article in Special Issue
LeanNet: An Efficient Convolutional Neural Network for Digital Number Recognition in Industrial Products
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition

by
Sheeba Lal
1,
Saeed Ur Rehman
1,
Jamal Hussain Shah
1,
Talha Meraj
1,
Hafiz Tayyab Rauf
2,*,
Robertas Damaševičius
3,*,
Mazin Abed Mohammed
4 and
Karrar Hameed Abdulkareem
5
1
Department of Computer Science, COMSATS University Islamabad, Wah Campus, Wah Cantt 47040, Pakistan
2
Department of Computer Science, Faculty of Engineering & Informatics, University of Bradford, Bradford BD7 1DP, UK
3
Faculty of Applied Mathematics, Silesian University of Technology, 44-100 Gliwice, Poland
4
College of Computer Science and Information Technology, University of Anbar, Anbar 31001, Iraq
5
College of Agriculture, Al-Muthanna University, Samawah 66001, Iraq
*
Authors to whom correspondence should be addressed.
Sensors 2021, 21(11), 3922; https://doi.org/10.3390/s21113922
Submission received: 2 May 2021 / Revised: 31 May 2021 / Accepted: 4 June 2021 / Published: 7 June 2021
(This article belongs to the Special Issue Deep Learning Image Recognition Systems)

Abstract

Due to the rapid growth in artificial intelligence (AI) and deep learning (DL) approaches, the security and robustness of the deployed algorithms need to be guaranteed. The security susceptibility of the DL algorithms to adversarial examples has been widely acknowledged. The artificially created examples will lead to different instances negatively identified by the DL models that are humanly considered benign. Practical application in actual physical scenarios with adversarial threats shows their features. Thus, adversarial attacks and defense, including machine learning and its reliability, have drawn growing interest and, in recent years, has been a hot topic of research. We introduce a framework that provides a defensive model against the adversarial speckle-noise attack, the adversarial training, and a feature fusion strategy, which preserves the classification with correct labelling. We evaluate and analyze the adversarial attacks and defenses on the retinal fundus images for the Diabetic Retinopathy recognition problem, which is considered a state-of-the-art endeavor. Results obtained on the retinal fundus images, which are prone to adversarial attacks, are 99% accurate and prove that the proposed defensive model is robust.
Keywords: diabetic retinopathy; adversarial attack; speckle-noise attack; adversarial training; feature fusion; deep learning diabetic retinopathy; adversarial attack; speckle-noise attack; adversarial training; feature fusion; deep learning

Share and Cite

MDPI and ACS Style

Lal, S.; Rehman, S.U.; Shah, J.H.; Meraj, T.; Rauf, H.T.; Damaševičius, R.; Mohammed, M.A.; Abdulkareem, K.H. Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition. Sensors 2021, 21, 3922. https://doi.org/10.3390/s21113922

AMA Style

Lal S, Rehman SU, Shah JH, Meraj T, Rauf HT, Damaševičius R, Mohammed MA, Abdulkareem KH. Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition. Sensors. 2021; 21(11):3922. https://doi.org/10.3390/s21113922

Chicago/Turabian Style

Lal, Sheeba, Saeed Ur Rehman, Jamal Hussain Shah, Talha Meraj, Hafiz Tayyab Rauf, Robertas Damaševičius, Mazin Abed Mohammed, and Karrar Hameed Abdulkareem. 2021. "Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition" Sensors 21, no. 11: 3922. https://doi.org/10.3390/s21113922

APA Style

Lal, S., Rehman, S. U., Shah, J. H., Meraj, T., Rauf, H. T., Damaševičius, R., Mohammed, M. A., & Abdulkareem, K. H. (2021). Adversarial Attack and Defence through Adversarial Training and Feature Fusion for Diabetic Retinopathy Recognition. Sensors, 21(11), 3922. https://doi.org/10.3390/s21113922

Note that from the first issue of 2016, this journal uses article numbers instead of page numbers. See further details here.

Article Metrics

Back to TopTop