L. T. Kohn, J. M. Corrigan, M. S. Donaldson, et al., Errors in health care: a leading cause of death and injury (2000).
L. H. Garland, Studies on accuracy of diagnostic procedures, AJR 82 (1959) 25-38.
L. P. Busby, J. L. Courtier, C. M. Glastonbury, Bias in radiology: The how and why of misses and misinterpretations, RadioGraphics 38 (2018) 236-247. URL: https://doi.org/10.1148/rg.2018170107. doi:10.1148/rg.2018170107. arXiv:https://doi.org/10.1148/rg.2018170107, pMID: 29194009.
G. S. Lodwick, T. E. Keats, J. P. Dorst, The coding of roentgen images for computer analysis as applied to lung cancer, Radiology 81 (1963) 185-200. URL: https://doi.org/10.1148/81.2.185. doi:10.1148/81.2.185. arXiv:https://doi.org/10.1148/81.2.185, pMID: 14053755.
P. Rajpurkar, J. Irvin, K. Zhu, B. Yang, H. Mehta, T. Duan, D. Ding, A. Bagul, C. Langlotz, K. Shpanskaya, M. P. Lungren, A. Y. Ng, Chexnet: Radiologist-level pneumonia detection on chest x-rays with deep learning, 2017. arXiv:1711.05225.
L. Yao, J. Prosky, B. Covington, K. Lyman, A strong baseline for domain adaptation and generalization in medical imaging, 2019. arXiv:1904.01638.
C. Qin, D. Yao, Y. Shi, Z. Song, Computer-aided detection in chest radiography based on artificial intelligence: a survey, BioMedical Engineering OnLine 17 (2018).
E. H. P. Pooch, P. L. Ballester, R. C. Barros, Can we trust deep learning models diagnosis? the impact of domain shift in chest radiograph classification, 2020. arXiv:1909.01940.
I. M. Baltruschat, H. Nickisch, M. Grass, T. Knopp, A. Saalbach, Comparison of deep learning approaches for multi-label chest x-ray classification, 2019. arXiv:1803.02315.
L. Oakden-Rayner, Exploring large scale public medical image datasets, 2019. arXiv:1907.12720.
J. P. Cohen, M. Hashir, R. Brooks, H. Bertrand, On the limits of cross-domain generalization in automated x-ray prediction, 2020. arXiv:2002.02497.
S. Finlayson, I. Kohane, A. Beam, Adversarial attacks against medical deep learning systems (2018).
S. A. Taghanaki, A. Das, G. Hamarneh, Vulnerability analysis of chest x-ray image classification against adversarial attacks (2018). arXiv:1807.02905.
X. Ma, Y. Niu, L. Gu, Y. Wang, Y. Zhao, J. Bailey, F. Lu, Understanding adversarial attacks on deep learning based medical image analysis systems, Pattern Recognition 110 (2021) 107332. URL: https://www.sciencedirect.com/science/article/pii/S0031320320301357. doi:https://doi.org/10.1016/j. patcog.2020.107332.
X. Li, D. Zhu, Robust detection of adversarial attacks on medical images, in: 2020 IEEE 17th International Symposium on Biomedical Imaging (ISBI), 2020, pp. 1154-1158. doi:10.1109/ISBI45749.2020.9098628.
B. Biggio, B. Nelson, P. Laskov, Poisoning attacks against support vector machines, arXiv preprint arXiv:1206.6389 (2012).
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. Šrndić, P. Laskov, G. Giacinto, F. Roli, Evasion attacks against machine learning at test time, in: Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics), volume 8190 LNAI, 2013, pp. 387-402. URL: http://arxiv.org/abs/1708.06131http://dx.doi.org/10.1007/978-3-642-40994-3_25. doi:10. 1007/978-3-642-40994-325.
I. J. Goodfellow, J. Shlens, C. Szegedy, Explaining and harnessing adversarial examples (2015). arXiv:1412.6572.
A. Kurakin, I. Goodfellow, S. Bengio, Adversarial machine learning at scale, arXiv preprint arXiv:1611.01236 (2016).
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks (2019). arXiv:1706.06083.
Y. Dong, F. Liao, T. Pang, H. Su, J. Zhu, X. Hu, J. Li, Boosting adversarial attacks with momentum, in: Proceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 9185-9193.
F. Croce, M. Hein, Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks (2020). arXiv:2003.01690.
T. Simonetto, S. Dyrmishi, S. Ghamizi, M. Cordy, Y. L. Traon, A unified framework for adversarial attack and defense in constrained feature space, arXiv preprint arXiv:2112.01156 (2021).
S. Ghamizi, M. Cordy, M. Gubri, M. Papadakis, A. Boystov, Y. Le Traon, A. Goujon, Search-based adversarial testing and improvement of constrained credit scoring systems, in: Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering, ESEC/FSE 2020, Association for Computing Machinery, New York, NY, USA, 2020, p. 1089-1100. URL: https://doi.org/10.1145/3368089.3409739.doi:10.1145/3368089.3409739.
S. Ghamizi, M. Cordy, M. Papadakis, Y. Le Traon, Evasion attack steganography: Turning vulnerability of machine learning to adversarial attacks into a real-world application, in: Proceedings of the IEEE/CVF International Conference on Computer Vision (ICCV) Workshops, 2021, pp. 31-40.
S. Ghamizi, M. Cordy, M. Papadakis, Y. L. Traon, Adversarial robustness in multi-task learning: Promises and illusions, Proceedings of the AAAI Conference on Artificial Intelligence 36 (2022) 697-705. URL: https://ojs.aaai.org/index.php/AAAI/article/view/19950. doi:10.1609/aaai.v36i1.19950.
S. Asgari Taghanaki, A. Das, G. Hamarneh, Vulnerability analysis of chest x-ray image classification against adversarial attacks, in: Understanding and interpreting machine learning in medical image computing applications, Springer, 2018, pp. 87-94.
X. Wang, Y. Peng, L. Lu, Z. Lu, M. Bagheri, R. M. Summers, Chestx-ray8: Hospital-scale chest x-ray database and benchmarks on weakly-supervised classification and localization of common thorax diseases, 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR) (2017). URL: http://dx.doi.org/10.1109/CVPR.2017.369. doi:10.1109/cvpr. 2017.369.
S. G. Finlayson, H. W. Chung, I. S. Kohane, A. L. Beam, Adversarial attacks against medical deep learning systems, arXiv preprint arXiv:1804.05296 (2018).
X. Ma, Y. Niu, L. Gu, Y. Wang, Y. Zhao, J. Bailey, F. Lu, Understanding adversarial attacks on deep learning based medical image analysis systems, Pattern Recognition 110 (2021) 107332.
J. Deng, W. Dong, R. Socher, L.-J. Li, K. Li, L. Fei-Fei, Imagenet: A large-scale hierarchical image database, in: 2009 IEEE conference on computer vision and pattern recognition, Ieee, 2009, pp. 248-255.
A. Krizhevsky, Learning multiple layers of features from tiny images, University of Toronto (2012).
G. de Lacey, S. Morley, L. Berman, 1 - chest radiology: The basic basics, in: G. de Lacey, S. Morley, L. Berman (Eds.), The Chest X-Ray: A Survival Guide, W.B. Saunders, Edinburgh, 2008, pp. 2-13. URL: https://www.sciencedirect.com/science/article/pii/B9780702030468500065. doi:https://doi. org/10.1016/B978-0-7020-3046-8.50006-5.
J. R. Ledford, Chest radiology: Plain film patterns and differential diagnoses, 6th ed., American Journal of Roentgenology 197 (2011) W1159-W1159. URL: https://doi.org/10.2214/AJR.11.7214. doi:10.2214/AJR.11.7214. arXiv:https://doi.org/10.2214/AJR.11.7214.
K. D. Apostolidis, G. A. Papakostas, A survey on adversarial deep learning robustness in medical image analysis, Electronics 10 (2021) 2132.
S. Kaviani, K. J. Han, I. Sohn, Adversarial attacks and defenses on ai in medical imaging informatics: A survey, Expert Systems with Applications (2022) 116815.
B. Tian, Q. Guo, F. Juefei-Xu, W. Le Chan, Y. Cheng, X. Li, X. Xie, S. Qin, Bias field poses a threat to dnn-based x-ray recognition, in: 2021 IEEE international conference on multimedia and expo (ICME), IEEE, 2021, pp. 1-6.
H. Hirano, K. Koga, K. Takemoto, Vulnerability of deep neural networks for detecting covid-19 cases from chest x-ray images to universal adversarial attacks, Plos one 15 (2020) e0243963.
B. Pal, D. Gupta, M. Rashed-Al-Mahfuz, S. A. Alyami, M. A. Moni, Vulnerability in deep transfer learning models to adversarial fast gradient sign attack for covid-19 prediction from chest radiography images, Applied Sciences 11 (2021) 4233.
C. Gongye, H. Li, X. Zhang, M. Sabbagh, G. Yuan, X. Lin, T. Wahl, Y. Fei, New passive and active attacks on deep neural networks in medical applications, in: Proceedings of the 39th international conference on computer-aided design, 2020, pp. 1-9.
A. Rahman, M. S. Hossain, N. A. Alrajeh, F. Alsolami, Adversarial examples-security threats to covid-19 deep learning systems in medical iot devices, IEEE Internet of Things Journal 8 (2020) 9603-9610.
D. Anand, D. Tank, H. Tibrewal, A. Sethi, Self-supervision vs. transfer learning: robust biomedical image analysis against adversarial attacks, in: 2020 IEEE 17th International Symposium on Biomedical Imaging (ISBI), IEEE, 2020, pp. 1159-1163.
V. Kovalev, D. Voynov, Influence of control parameters and the size of biomedical image datasets on the success of adversarial attacks, in: International Conference on Pattern Recognition and Information Processing, Springer, 2019, pp. 301-311.
H. Hirano, A. Minagi, K. Takemoto, Universal adversarial attacks on deep neural networks for medical image classification, BMC medical imaging 21 (2021) 1-13.
F.-F. Xue, J. Peng, R. Wang, Q. Zhang, W.-S. Zheng, Improving robustness of medical image diagnosis with denoising convolutional neural networks, in: International Conference on Medical Image Computing and Computer-Assisted Intervention, Springer, 2019, pp. 846-854.
A. M. Tripathi, A. Mishra, Fuzzy unique image transformation: Defense against adversarial attacks on deep covid-19 models, arXiv preprint arXiv:2009.04004 (2020).
M. Xu, T. Zhang, Z. Li, M. Liu, D. Zhang, Towards evaluating the robustness of deep diagnostic models by adversarial attack, Medical Image Analysis 69 (2021) 101977.
X. Li, D. Zhu, Robust detection of adversarial attacks on medical images, in: 2020 IEEE 17th International Symposium on Biomedical Imaging (ISBI), IEEE, 2020, pp. 1154-1158.
A. Madry, A. Makelov, L. Schmidt, D. Tsipras, A. Vladu, Towards deep learning models resistant to adversarial attacks, arXiv preprint arXiv:1706.06083 (2017).
A. Athalye, N. Carlini, D. Wagner, Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples, 2018. arXiv:1802.00420.
W. He, J. Wei, X. Chen, N. Carlini, D. Song, Adversarial example defense: Ensembles of weak defenses are not strong, in: 11th (USENIX) workshop on offensive technologies ((WOOT) 17), 2017.
N. Carlini, A. Athalye, N. Papernot, W. Brendel, J. Rauber, D. Tsipras, I. Goodfellow, A. Madry, A. Kurakin, On evaluating adversarial robustness, 2019. arXiv:1902.06705.
F. Croce, M. Andriushchenko, V. Sehwag, E. Debenedetti, N. Flammarion, M. Chiang, P. Mittal, M. Hein, Robustbench: a standardized adversarial robustness benchmark, arXiv preprint arXiv:2010.09670 (2020).
M. Paschali, S. Conjeti, F. Navarro, N. Navab, Generalizability vs. robustness: Adversarial examples for medical imaging, 2018. arXiv:1804.00504.
J. Irvin, P. Rajpurkar, M. Ko, Y. Yu, S. Ciurea-Ilcus, C. Chute, H. Marklund, B. Haghgoo, R. Ball, K. Shpanskaya, J. Seekins, D. A. Mong, S. S. Halabi, J. K. Sandberg, R. Jones, D. B. Larson, C. P. Langlotz, B. N. Patel, M. P. Lungren, A. Y. Ng, Chexpert: A large chest radiograph dataset with uncertainty labels and expert comparison, 2019. arXiv:1901.07031.
A. Bustos, A. Pertusa, J.-M. Salinas, M. de la Iglesia-Vayá, Pad-chest: A large chest x-ray image dataset with multi-label annotated reports, Medical Image Analysis 66 (2020) 101797. URL: http://dx.doi.org/10.1016/j.media.2020.101797. doi:10.1016/j.media.2020.101797.