Decorrelative Network Architecture for Robust Electrocardiogram Classification (2207.09031v4)
Abstract: Artificial intelligence has made great progress in medical data analysis, but the lack of robustness and trustworthiness has kept these methods from being widely deployed. As it is not possible to train networks that are accurate in all scenarios, models must recognize situations where they cannot operate confidently. Bayesian deep learning methods sample the model parameter space to estimate uncertainty, but these parameters are often subject to the same vulnerabilities, which can be exploited by adversarial attacks. We propose a novel ensemble approach based on feature decorrelation and Fourier partitioning for teaching networks diverse complementary features, reducing the chance of perturbation-based fooling. We test our approach on single and multi-channel electrocardiogram classification, and adapt adversarial training and DVERGE into the Bayesian ensemble framework for comparison. Our results indicate that the combination of decorrelation and Fourier partitioning generally maintains performance on unperturbed data while demonstrating superior robustness and uncertainty estimation on projected gradient descent and smooth adversarial attacks of various magnitudes. Furthermore, our approach does not require expensive optimization with adversarial samples, adding much less compute to the training process than adversarial training or DVERGE. These methods can be applied to other tasks for more robust and trustworthy models.
- Application of deep learning techniques for heartbeats detection using ECG signals-analysis and review. Computers in Biology and Medicine, 120:103726, 2020.
- Ulecgnet: An ultra-lightweight end-to-end ecg classification neural network. IEEE Journal of Biomedical and Health Informatics, 26(1):206–217, 2022.
- Opportunities and challenges of deep learning methods for electrocardiogram data: A systematic review. Computers in Biology and Medicine, 122, 2020.
- Af classification from a short single lead ECG recording: the physionet computing in cardiology challenge 2017, 2017.
- An open access database for evaluating the algorithms of electrocardiogram rhythm and morphology abnormality detection. Journal of Medical Imaging and Health Informatics, 8:1368–1373, 09 2018.
- Towards understanding ECG rhythm classification using convolutional neural networks and attention mappings. In Proceedings of the 3rd Machine Learning for Healthcare Conference, pages 83–101. PMLR, 2018. ISSN: 2640-3498.
- Intriguing properties of neural networks, 2014.
- Towards deep learning models resistant to adversarial attacks. arXiv:1706.06083 [cs, stat], 2019.
- Adversarial attacks and defenses in deep learning. Engineering, 6(3):346–360, 2020.
- Constructing unrestricted adversarial examples with generative models. arXiv:1805.07894 [cs, stat], 2018.
- Generating adversarial examples with adversarial networks. arXiv:1801.02610 [cs, stat], 2019.
- Rob-GAN: Generator, discriminator, and adversarial attacker. arXiv:1807.10454 [cs, stat], 2019.
- DeepFool: a simple and accurate method to fool deep neural networks. arXiv:1511.04599 [cs], 2016.
- Universal adversarial perturbations: A survey. arXiv:2005.08087 [cs], 2020.
- Threat of adversarial attacks on deep learning in computer vision: A survey. IEEE Access, 6:14410–14430, 2018. Conference Name: IEEE Access.
- Explaining and harnessing adversarial examples. arXiv:1412.6572 [cs, stat], 2015.
- Transferability in machine learning: from phenomena to black-box attacks using adversarial samples. arXiv:1605.07277 [cs], 2016.
- Adversarial spheres. arXiv:1801.02774 [cs], 2018.
- Simant Dube. High dimensional spaces, deep learning and adversarial examples. arXiv:1801.00634 [cs], 2018.
- Adversarial robustness through local linearization. arXiv:1907.02610 [cs, stat], 2019.
- Formal guarantees on the robustness of a classifier against adversarial manipulation. Advances in Neural Information Processing Systems, 30, 2017.
- Adversarial training is a form of data-dependent operator norm regularization. arXiv:1906.01527 [cs, stat], 2020-10-23.
- Adversarial examples are not bugs, they are features. arXiv:1905.02175 [cs, stat], 2019.
- Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples. arXiv:1802.00420 [cs], 2018.
- Adversarial examples are not easily detected: Bypassing ten detection methods. arXiv:1705.07263 [cs], 2017.
- Adversarial risk and the dangers of evaluating against weak attacks. arXiv:1802.05666 [cs, stat], 2018.
- Defensive distillation is not robust to adversarial examples. arXiv:1607.04311 [cs], 2016.
- Distillation as a defense to adversarial perturbations against deep neural networks. arxiv, 2016.
- Adversarial examples in the physical world. arXiv:1607.02533 [cs, stat], 2017.
- A fourier perspective on model robustness in computer vision. In H. Wallach, H. Larochelle, A. Beygelzimer, F. d’ Alché-Buc, E. Fox, and R. Garnett, editors, Advances in Neural Information Processing Systems, volume 32. Curran Associates, Inc., 2019.
- The space of transferable adversarial examples. arXiv:1704.03453 [cs, stat], 2017.
- Deep learning models for electrocardiograms are susceptible to adversarial attack. Nature Medicine, 26(3):360–363, 2020.
- Comprehensive survey of computational ECG analysis: Databases, methods and applications. Expert Systems with Applications, 203:117206, October 2022.
- Atrial fibrillation and the risk for myocardial infarction, all-cause mortality and heart failure: A systematic review and meta-analysis. European Journal of Preventive Cardiology, 24(14):1555–1566, September 2017.
- Implantable loop recorder detection of atrial fibrillation to prevent stroke (The LOOP Study): a randomised controlled trial. The Lancet, 398(10310):1507–1516, October 2021.
- A review on deep learning methods for ECG arrhythmia classification. Expert Systems with Applications: X, 7:100033, 2020.
- Meeting the unmet needs of clinicians from ai systems showcased for cardiology with deep-learning–based ecg analysis. Proceedings of the National Academy of Sciences, 118(24):e2020620118, 2021.
- Andrew Gordon Wilson. The case for bayesian deep learning, 2020. Number: arXiv:2001.10995.
- Bayesian deep learning and a probabilistic perspective of generalization. In Advances in Neural Information Processing Systems, volume 33, pages 4697–4708. Curran Associates, Inc., 2020.
- Alex Graves. Practical variational inference for neural networks. In NIPS, 2011.
- Radford Neal. Bayesian learning via stochastic dynamics. In NIPS, 1992.
- Simple and scalable predictive uncertainty estimation using deep ensembles. In NIPS, 2017.
- Christopher Wiedeman and Ge Wang. Disrupting adversarial transferability in deep neural networks. Patterns, page 100472, 2022.
- DVERGE: Diversifying vulnerabilities for enhanced robust generation of ensembles. arXiv:2009.14720 [cs, stat], 2020.
- Dropout as a bayesian approximation: Representing model uncertainty in deep learning. International Conference of Machine Learning, 48, 2016.
- Bayesian segnet: Model uncertainty in deep convolutional encoder-decoder architectures for scene understanding. In Proceedings of the British Machine Vision Conference, pages 57.1–57.12. BMVA Press, 2017.
- Dropconnect is effective in modeling uncertainty of bayesian deep networks. Scientific Reports, 11(5458), 2021.
Sponsor
Paper Prompts
Sign up for free to create and run prompts on this paper using GPT-5.
Top Community Prompts
Collections
Sign up for free to add this paper to one or more collections.