Injecting and removing suspicious features in breast imaging with CycleGAN: A pilot study of automated adversarial attacks using neural networks on small images

Eur J Radiol. 2019 Nov:120:108649. doi: 10.1016/j.ejrad.2019.108649. Epub 2019 Sep 10.

Abstract

Purpose: To train a CycleGAN on downscaled versions of mammographic data to artificially inject or remove suspicious features, and to determine whether these AI-mediated attacks can be detected by radiologists.

Material and methods: From two publicly available datasets, BCDR and INbreast, we selected 680 images with and without lesions as training data. An internal dataset (n = 302 cancers, n = 590 controls) served as test data. We ran two experiments (256 × 256 px and 512 × 408 px) and applied the trained model to the test data. Three radiologists read a set of images (modified and originals) and rated the presence of suspicious lesions on a scale from 1 to 5 and the likelihood of the image being manipulated. The readout was evaluated by multiple reader multiple case receiver operating characteristics (MRMC-ROC) analysis using the area under the curve (AUC).

Results: At the lower resolution, the overall performance was not affected by the CycleGAN modifications (AUC 0.70 vs. 0.76, p = 0.67). However, one radiologist exhibited lower detection of cancer (0.85 vs 0.63, p = 0.06). The radiologists could not discriminate between original and modified images (0.55, p = 0.45). At the higher resolution, all radiologists showed significantly lower detection rate of cancer in the modified images (0.80 vs. 0.37, p < 0.001), however, they were able to detect modified images due to better visibility of artifacts (0.94, p < 0.0001).

Conclusion: Our proof-of-concept study shows that CycleGAN can implicitly learn suspicious features and artificially inject or remove them in existing images. The applicability of the method is currently limited by the small image size and introduction of artifacts.

Keywords: Cancer; Cyber security; GAN; Mammography.

Publication types

  • Evaluation Study

MeSH terms

  • Area Under Curve
  • Breast / pathology
  • Breast Neoplasms / diagnostic imaging
  • Breast Neoplasms / pathology*
  • Case-Control Studies
  • Female
  • Humans
  • Image Interpretation, Computer-Assisted / methods
  • Mammography / methods*
  • Neural Networks, Computer*
  • Pilot Projects
  • ROC Curve
  • Radiologists