Localized adversarial artifacts for compressed sensing MRI

Alaifari, Rima, Alberti, Giovanni S., Gauksson, Tandri

arXiv.org Artificial Intelligence 

Following the success of deep learning in computer vision, deep neural networks (DNNs) have now found their way to a wide range of imaging inverse problems [3, 19, 20]. In some applications, learning the distribution of images from data is the only option. In others, existing methods based on hand-crafted priors are well established. Magnetic resonance imaging (MRI) reconstruction, for which sparsity-based methods have been highly successful, is an example of the latter [17]. However, recent work suggests that image quality can be improved and computation times shortened significantly by the use of DNNs in MRI reconstruction [9]. At the same time, it is well known that DNNs trained for image classification admit socalled adversarial examples--images that have been altered in minor but very specific ways to change the label predicted by the network [4, 22]. In [2], it was discovered that DNNs used in inverse problems (MRI and computed tomography) exhibit similar behavior. Namely, the authors show that perturbing the measurements slightly can lead to undesirable artifacts in the image reconstructed by the network and that the same perturbations do not cause problems for state-of-the-art compressed sensing methods. On the other hand, [13] shows quantitatively that DNNs can be made robust, to a comparable level with total variation (TV) minimization, by injecting statistical noise to the measurement data during training.