1
Return

Slice-sparse: few-slice adversarial attacks for 3D medical segmentation

delete2026-08-12
delete0
PRE
AI
H
Hyun Kwon
D
Dae-Jin Kim *
DOI:10.1007/s13042-026-03265-4delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Robustness of 3D medical image segmentation to adversarial perturbations is commonly assessed under dense, volume-wide attacks or frequency/shape priors, leaving a critical gap for slice-sparse threats that modify only a few axial sections of a volume. We introduce Slice-Sparse, a protocol and attack that enforces a strict budget of k perturbed slices per case while remaining compatible with sliding-window inference used by modern 3D U-Nets. Our method ranks slices by gradient-based loss sensitivity computed in a window-aware manner and applies a masked, iterative PGD update confined to the selected slices, with optional periodic re-selection to track the evolving loss landscape; all perturbations are bounded in $$\ell _\infty $$ . On the MSD Task02 Heart benchmark with a MONAI 3D U-Net trained for binary segmentation, perturbing only $$k\!=\!4$$ of $$\sim \!267$$ slices on average ( $$\approx \!1.5\%$$ of the volume) under $$\epsilon \!=\!1.0$$ reduces mean Dice from $$0.7413\!\pm \!0.0324$$ to $$0.3058\!\pm \!0.1495$$ (absolute drop 0.4355,   $$58.29\%$$ relative), while preserving high volume-wide similarity to the clean input (SSIM $$\approx \!0.9898$$ , PSNR $$\approx \!36.8$$  dB averaged across the full volume; localized intensity changes remain within the $$\ell _\infty $$ budget on the perturbed slices). Compared with random slice selection and one-step sparse baselines, Slice-Sparse yields substantially larger performance degradation under the same sparsity budget, demonstrating the importance of gradient-ranked slice targeting. Ablations over k, step size, iteration count, perturbation radius, and re-selection interval corroborate stable, controllable trade-offs between stealth (few perturbed slices, high SSIM) and attack strength (Dice drop). By formalizing and evaluating this few-slice adversarial threat model, our study exposes a previously under-explored vulnerability of volumetric segmentation and provides a practical benchmark for developing slice-aware defenses.
Keywords:
Adversarial robustness
Slice-sparse attack
Masked projected gradient
3D medical image segmentation

Journal

International Journal of Machine Learning and Cybernetics cover
International Journal of Machine Learning and Cybernetics
IF:
2.7
Papers:
3.1K
Citations:
5.6K

Organization

D
Department of Architectural Engineering
Scholars:
53
Papers: 32
Citations: 0
Cited Papers

Cited Papers

Citing Papers

Citing Papers