<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1d3 20150301//EN" "http://jats.nlm.nih.gov/publishing/1.1d3/JATS-journalpublishing1.dtd">
<article article-type="research-article" dtd-version="1.1d3" xml:lang="en" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">
<front>
<journal-meta>
<journal-id journal-id-type="nlm-ta">PLoS ONE</journal-id>
<journal-id journal-id-type="publisher-id">plos</journal-id>
<journal-id journal-id-type="pmc">plosone</journal-id>
<journal-title-group>
<journal-title>PLOS ONE</journal-title>
</journal-title-group>
<issn pub-type="epub">1932-6203</issn>
<publisher>
<publisher-name>Public Library of Science</publisher-name>
<publisher-loc>San Francisco, CA USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.1371/journal.pone.0243963</article-id>
<article-id pub-id-type="publisher-id">PONE-D-20-21731</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Research Article</subject>
</subj-group>
<subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Medical conditions</subject><subj-group><subject>Infectious diseases</subject><subj-group><subject>Viral diseases</subject><subj-group><subject>COVID 19</subject></subj-group></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Diagnostic medicine</subject><subj-group><subject>Virus testing</subject></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Pulmonology</subject><subj-group><subject>Pneumonia</subject></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Diagnostic medicine</subject><subj-group><subject>Diagnostic radiology</subject><subj-group><subject>Bone imaging</subject><subj-group><subject>X-ray radiography</subject></subj-group></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Research and analysis methods</subject><subj-group><subject>Imaging techniques</subject><subj-group><subject>Diagnostic radiology</subject><subj-group><subject>Bone imaging</subject><subj-group><subject>X-ray radiography</subject></subj-group></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Radiology and imaging</subject><subj-group><subject>Diagnostic radiology</subject><subj-group><subject>Bone imaging</subject><subj-group><subject>X-ray radiography</subject></subj-group></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Diagnostic medicine</subject><subj-group><subject>Diagnostic radiology</subject><subj-group><subject>X-ray radiography</subject></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Research and analysis methods</subject><subj-group><subject>Imaging techniques</subject><subj-group><subject>Diagnostic radiology</subject><subj-group><subject>X-ray radiography</subject></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Medicine and health sciences</subject><subj-group><subject>Radiology and imaging</subject><subj-group><subject>Diagnostic radiology</subject><subj-group><subject>X-ray radiography</subject></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Social sciences</subject><subj-group><subject>Sociology</subject><subj-group><subject>Education</subject><subj-group><subject>Training (education)</subject><subj-group><subject>Retraining</subject></subj-group></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Research and analysis methods</subject><subj-group><subject>Imaging techniques</subject></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Computer and information sciences</subject><subj-group><subject>Neural networks</subject></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Biology and life sciences</subject><subj-group><subject>Neuroscience</subject><subj-group><subject>Neural networks</subject></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Physical sciences</subject><subj-group><subject>Mathematics</subject><subj-group><subject>Applied mathematics</subject><subj-group><subject>Algorithms</subject></subj-group></subj-group></subj-group></subj-group><subj-group subj-group-type="Discipline-v3">
<subject>Research and analysis methods</subject><subj-group><subject>Simulation and modeling</subject><subj-group><subject>Algorithms</subject></subj-group></subj-group></subj-group></article-categories>
<title-group>
<article-title>Vulnerability of deep neural networks for detecting COVID-19 cases from chest X-ray images to universal adversarial attacks</article-title>
<alt-title alt-title-type="running-head">Vulnerability of AI for COVID-19 detection from radiographs</alt-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" xlink:type="simple">
<name name-style="western">
<surname>Hirano</surname>
<given-names>Hokuto</given-names>
</name>
<role content-type="https://casrai.org/credit/">Data curation</role>
<role content-type="https://casrai.org/credit/">Formal analysis</role>
<role content-type="https://casrai.org/credit/">Investigation</role>
<role content-type="https://casrai.org/credit/">Methodology</role>
<role content-type="https://casrai.org/credit/">Software</role>
<role content-type="https://casrai.org/credit/">Validation</role>
<role content-type="https://casrai.org/credit/">Visualization</role>
<role content-type="https://casrai.org/credit/">Writing – original draft</role>
<xref ref-type="aff" rid="aff001"/>
</contrib>
<contrib contrib-type="author" xlink:type="simple">
<name name-style="western">
<surname>Koga</surname>
<given-names>Kazuki</given-names>
</name>
<role content-type="https://casrai.org/credit/">Investigation</role>
<role content-type="https://casrai.org/credit/">Methodology</role>
<xref ref-type="aff" rid="aff001"/>
</contrib>
<contrib contrib-type="author" corresp="yes" xlink:type="simple">
<contrib-id authenticated="true" contrib-id-type="orcid">https://orcid.org/0000-0002-6355-1366</contrib-id>
<name name-style="western">
<surname>Takemoto</surname>
<given-names>Kazuhiro</given-names>
</name>
<role content-type="https://casrai.org/credit/">Conceptualization</role>
<role content-type="https://casrai.org/credit/">Formal analysis</role>
<role content-type="https://casrai.org/credit/">Investigation</role>
<role content-type="https://casrai.org/credit/">Methodology</role>
<role content-type="https://casrai.org/credit/">Project administration</role>
<role content-type="https://casrai.org/credit/">Supervision</role>
<role content-type="https://casrai.org/credit/">Validation</role>
<role content-type="https://casrai.org/credit/">Visualization</role>
<role content-type="https://casrai.org/credit/">Writing – original draft</role>
<role content-type="https://casrai.org/credit/">Writing – review &amp; editing</role>
<xref ref-type="aff" rid="aff001"/>
<xref ref-type="corresp" rid="cor001">*</xref>
</contrib>
</contrib-group>
<aff id="aff001"><addr-line>Department of Bioscience and Bioinformatics, Kyushu Institute of Technology, Iizuka, Fukuoka, Japan</addr-line></aff>
<contrib-group>
<contrib contrib-type="editor" xlink:type="simple">
<name name-style="western">
<surname>Xie</surname>
<given-names>Haoran</given-names>
</name>
<role>Editor</role>
<xref ref-type="aff" rid="edit1"/>
</contrib>
</contrib-group>
<aff id="edit1"><addr-line>Lingnan University, HONG KONG</addr-line></aff>
<author-notes>
<fn fn-type="conflict" id="coi001">
<p>The authors have declared that no competing interests exist.</p>
</fn>
<corresp id="cor001">* E-mail: <email xlink:type="simple">takemoto@bio.kyutech.ac.jp</email></corresp>
</author-notes>
<pub-date pub-type="epub">
<day>17</day>
<month>12</month>
<year>2020</year>
</pub-date>
<pub-date pub-type="collection">
<year>2020</year>
</pub-date>
<volume>15</volume>
<issue>12</issue>
<elocation-id>e0243963</elocation-id>
<history>
<date date-type="received">
<day>13</day>
<month>7</month>
<year>2020</year>
</date>
<date date-type="accepted">
<day>2</day>
<month>12</month>
<year>2020</year>
</date>
</history>
<permissions>
<copyright-year>2020</copyright-year>
<copyright-holder>Hirano et al</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/" xlink:type="simple">
<license-p>This is an open access article distributed under the terms of the <ext-link ext-link-type="uri" xlink:href="http://creativecommons.org/licenses/by/4.0/" xlink:type="simple">Creative Commons Attribution License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original author and source are credited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="info:doi/10.1371/journal.pone.0243963"/>
<abstract>
<p>Owing the epidemic of the novel coronavirus disease 2019 (COVID-19), chest X-ray computed tomography imaging is being used for effectively screening COVID-19 patients. The development of computer-aided systems based on deep neural networks (DNNs) has become an advanced open source to rapidly and accurately detect COVID-19 cases because the need for expert radiologists, who are limited in number, forms a bottleneck for screening. However, thus far, the vulnerability of DNN-based systems has been poorly evaluated, although realistic and high-risk attacks using universal adversarial perturbation (UAP), a single (input image agnostic) perturbation that can induce DNN failure in most classification tasks, are available. Thus, we focus on representative DNN models for detecting COVID-19 cases from chest X-ray images and evaluate their vulnerability to UAPs. We consider non-targeted UAPs, which cause a task failure, resulting in an input being assigned an incorrect label, and targeted UAPs, which cause the DNN to classify an input into a specific class. The results demonstrate that the models are vulnerable to non-targeted and targeted UAPs, even in the case of small UAPs. In particular, the 2% norm of the UAPs to the average norm of an image in the image dataset achieves &gt;85% and &gt;90% success rates for the non-targeted and targeted attacks, respectively. Owing to the non-targeted UAPs, the DNN models judge most chest X-ray images as COVID-19 cases. The targeted UAPs allow the DNN models to classify most chest X-ray images into a specified target class. The results indicate that careful consideration is required in practical applications of DNNs to COVID-19 diagnosis; in particular, they emphasize the need for strategies to address security concerns. As an example, we show that iterative fine-tuning of DNN models using UAPs improves the robustness of DNN models against UAPs.</p>
</abstract>
<funding-group>
<funding-statement>The authors received no specific funding for this work.</funding-statement>
</funding-group>
<counts>
<fig-count count="5"/>
<table-count count="3"/>
<page-count count="15"/>
</counts>
<custom-meta-group>
<custom-meta id="data-availability">
<meta-name>Data Availability</meta-name>
<meta-value>The code used in this study is available from our GitHub repository: <ext-link ext-link-type="uri" xlink:href="http://github.com/hkthirano/UAP-COVID-Net" xlink:type="simple">github.com/hkthirano/UAP-COVID-Net</ext-link>. The chest X-ray images used in this study are publicly available online (see <ext-link ext-link-type="uri" xlink:href="http://github.com/lindawangg/COVID-Net/blob/master/docs/COVIDx.md" xlink:type="simple">github.com/lindawangg/COVID-Net/blob/master/docs/COVIDx.md</ext-link> for details).</meta-value>
</custom-meta>
<custom-meta id="outbreaks">
<meta-name>Outbreaks</meta-name>
<meta-value>COVID-19</meta-value>
</custom-meta>
</custom-meta-group>
</article-meta>
</front>
<body>
<sec id="sec001" sec-type="intro">
<title>Introduction</title>
<p>Coronavirus disease 2019 (COVID-19) [<xref ref-type="bibr" rid="pone.0243963.ref001">1</xref>] is an infectious disease caused by the coronavirus, called severe acute respiratory syndrome coronavirus 2. The COVID-19 epidemic started from Wuhan, China [<xref ref-type="bibr" rid="pone.0243963.ref002">2</xref>], and has had a severe impact on public health and the economy globally [<xref ref-type="bibr" rid="pone.0243963.ref003">3</xref>]. To reduce the spread of this epidemic, effective screening of COVID-19 patients is required. Thus, positive real-time polymerase chain reaction (PCR) tests are mainly used [<xref ref-type="bibr" rid="pone.0243963.ref004">4</xref>]; however, they are often time consuming and laborious and involve complicated manual processes. Chest radiography, especially chest X-ray computed tomography (CT) imaging, becomes an alternative screening method [<xref ref-type="bibr" rid="pone.0243963.ref005">5</xref>] because patients present abnormalities in chest radiography images, which are a characteristic of those infected with COVID-19 [<xref ref-type="bibr" rid="pone.0243963.ref002">2</xref>, <xref ref-type="bibr" rid="pone.0243963.ref006">6</xref>]. Moreover, there are advantages to leveraging chest X-ray imaging for COVID-19 screening amid the pandemic in terms of rapid triaging, portability, availability, and accessibility [<xref ref-type="bibr" rid="pone.0243963.ref007">7</xref>]. However, the visual differences in chest X-ray images among COVID-19-associated pneumonia, non-COVID-19 pneumonia, and no pneumonia are subtle; thus, the need for expert radiologists, who are limited in number, forms a bottleneck for diagnoses based on radiography images. To overcome this limitation, computer-aided systems that can aid radiologists in more rapidly and accurately interpreting radiography images to detect COVID-19 cases are highly required [<xref ref-type="bibr" rid="pone.0243963.ref007">7</xref>, <xref ref-type="bibr" rid="pone.0243963.ref008">8</xref>]; in particular, deep neural networks (DNNs) are often used for this purpose.</p>
<p>DNNs are widely used for image classification, a task in which an input image is assigned a class from a fixed set of classes as well as medical science [<xref ref-type="bibr" rid="pone.0243963.ref009">9</xref>, <xref ref-type="bibr" rid="pone.0243963.ref010">10</xref>], including diagnoses based on radiography images. Specifically, DNN-based systems can detect subtle visual differences in the images; in particular, a DNN can accurately distinguish bacterial and viral pneumonia in chest X-ray images [<xref ref-type="bibr" rid="pone.0243963.ref011">11</xref>]. Inspired by these previous studies, many researchers have constructed large-scale datasets of chest radiography images on COVID-19 [<xref ref-type="bibr" rid="pone.0243963.ref007">7</xref>, <xref ref-type="bibr" rid="pone.0243963.ref008">8</xref>, <xref ref-type="bibr" rid="pone.0243963.ref012">12</xref>, <xref ref-type="bibr" rid="pone.0243963.ref013">13</xref>] and have proposed DNN-based systems for screening COVID-19 cases from these images [<xref ref-type="bibr" rid="pone.0243963.ref008">8</xref>, <xref ref-type="bibr" rid="pone.0243963.ref014">14</xref>–<xref ref-type="bibr" rid="pone.0243963.ref017">17</xref>]. However, DNN-based systems in medical science have generally been closed source and unavailable to the research community for deeper understanding and extension. Thus, Wang et al. [<xref ref-type="bibr" rid="pone.0243963.ref007">7</xref>] proposed COVID-Net, a deep convolutional neural network design intended to detect COVID-19 cases from chest X-ray images. COVID-Net is one of the first open-source network designs for COVID-19 detection. As the authors mentioned [<xref ref-type="bibr" rid="pone.0243963.ref007">7</xref>], this study will be leveraged and built upon by both researchers and citizen data scientists to accelerate the development of highly accurate yet practical deep learning solutions for detecting COVID-19 cases and accelerate the treatment of the disease. The COVID-Net models are intended to be used as reference models; in fact, several DNN-based systems [<xref ref-type="bibr" rid="pone.0243963.ref018">18</xref>–<xref ref-type="bibr" rid="pone.0243963.ref020">20</xref>] for detecting COVID-19 cases have already been proposed, inspired by the COVID-Net study.</p>
<p>However, previous studies have poorly evaluated the vulnerabilities in DNNs, although DNNs are known to be vulnerable to adversarial examples [<xref ref-type="bibr" rid="pone.0243963.ref021">21</xref>, <xref ref-type="bibr" rid="pone.0243963.ref022">22</xref>], which are input images that cause misclassifications by DNNs and are usually generated by adding specific, imperceptible perturbations to original input images that have been correctly classified using DNNs. Adversaries can easily attack open-sourced software, such as COVID-Net because they can access the model parameters and training data; thus, it is important to evaluate the reliability and safety of DNNs against adversarial attacks.</p>
<p>These adversarial attacks may be less useful for adversaries because they are input image dependent (i.e., an individual adversarial perturbation is used such that each input image is misclassified). However, more realistic adversarial attacks have been proposed in recent years. Notably, a single perturbation (called <italic>universal adversarial perturbation</italic>, <italic>UAP</italic>, as they are image agnostic) [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>] that can induce DNN failure in most image classification tasks also exists. UAPs are difficult to detect because such perturbations are extremely small and, hence, do not significantly affect data distributions. UAP-based adversarial attacks can be more straightforward to implement by adversaries in real-world environments. A previous study [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>] considered only UAPs for non-targeted attacks, which cause misclassification (i.e., a task failure resulting in an input image being assigned an incorrect class). However, we previously extended the algorithm for generating UAPs to enable targeted attacks [<xref ref-type="bibr" rid="pone.0243963.ref024">24</xref>], causing the DNN to classify an input image into a specific class. The existence of adversarial examples questions the generalization ability of DNNs, reduces model interpretability, and limits the applications of deep learning in safety- and security-critical environments [<xref ref-type="bibr" rid="pone.0243963.ref025">25</xref>]. Specifically, vulnerability is a severe problem in medical diagnosis [<xref ref-type="bibr" rid="pone.0243963.ref026">26</xref>]. Thus, it is important to evaluate the vulnerability of the proposed DNN-based systems to adversarial attacks (attacks based on UAPs, in particular) in practical applications. In addition, defense strategies against adversarial attacks (i.e., adversarial defense [<xref ref-type="bibr" rid="pone.0243963.ref022">22</xref>]) are required.</p>
<p>In this study, we focus on the COVID-Net models, which are representative models for detecting COVID-19 cases from chest X-ray images, and aim to evaluate the vulnerability of DNNs to adversarial attacks. Specifically, the vulnerability to non-targeted and targeted attacks, based on UAPs, is investigated. Moreover, adversarial defense is considered; in particular, we evaluate to what extent the robustness of COVID-Net models to non-targeted and targeted UAPs increases using adversarial retraining [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref027">27</xref>] (i.e., fine-tuning with adversarial images).</p>
</sec>
<sec id="sec002">
<title>Material and methods</title>
<sec id="sec003">
<title>COVID-Net models</title>
<p>We forked the COVID-Net repository (github.com/lindawangg/COVID-Net) on May 1, 2020, and obtained two DNN models for detecting COVID-19 cases from chest X-ray images: COVIDNet-CXR Small and COVIDNet-CXR Large. Moreover, we downloaded the COVIDx dataset, a collection of chest radiography images from several open-source chest radiography datasets, on May 1, 2020, according to the description in the COVID-Net repository. The chest X-ray images in the dataset were classified into three classes: <italic>normal</italic> (no pneumonia), <italic>pneumonia</italic> (non-COVID-19 pneumonia; e.g., viral and bacterial pneumonia), and <italic>COVID-19</italic> (COVID-19 viral pneumonia). The dataset comprised 13,569 training images (7,966 <italic>normal</italic> images, 5,451 <italic>pneumonia</italic> images, and 152 <italic>COVID-19</italic> images) and 231 test images (100 <italic>normal</italic> images, 100 <italic>pneumonia</italic> images, and 31 <italic>COVID-19</italic> images).</p>
</sec>
<sec id="sec004">
<title>Universal adversarial perturbations</title>
<p>The UAPs for non-targeted and targeted attacks were generated using simple iterative algorithms [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref028">28</xref>], whose details are described in [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref028">28</xref>]. We used the non-targeted UAP algorithm available in the Adversarial Robustness 360 Toolbox (ART) [<xref ref-type="bibr" rid="pone.0243963.ref029">29</xref>] (version 1.0; github.com/IBM/adversarial-robustness-toolbox). The targeted UAP algorithm was implemented by modifying the non-targeted UAP algorithm in the ART in our previous study [<xref ref-type="bibr" rid="pone.0243963.ref024">24</xref>] (github.com/hkthirano/targeted_UAP_CIFAR10).</p>
<p>The algorithms consider a classifier, <italic>C</italic>(<bold><italic>x</italic></bold>), which returns the class or label with the highest confidence score for an input image, <bold><italic>x</italic></bold>. The algorithm starts with <bold><italic>ρ</italic></bold> = <bold>0</bold> (no perturbation) and iteratively updates the UAP, <bold><italic>ρ</italic></bold>, under the constraint that the <italic>L</italic><sub><italic>p</italic></sub> norm of the perturbation is equal to or less than a small <italic>ξ</italic> value (i.e., ‖<bold><italic>ρ</italic></bold>‖<sub><italic>p</italic></sub> ≤ <italic>ξ</italic>), by additively obtaining an adversarial perturbation for an input image, <bold><italic>x</italic></bold>, which is randomly selected from an input image set, <bold><italic>X</italic></bold>, without replacement. These iterative updates continue until the number of iterations reaches a maximum <italic>i</italic><sub>max</sub>.</p>
<p>We used the fast gradient sign method (FGSM) [<xref ref-type="bibr" rid="pone.0243963.ref021">21</xref>] to obtain an adversarial perturbation for the input image, instead of the original UAP algorithm [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>], which uses the DeepFool method [<xref ref-type="bibr" rid="pone.0243963.ref030">30</xref>]. This is because FGSM is used for both non-targeted and targeted attacks, and DeepFool requires a higher computational cost than FGSM and only generates a non-targeted adversarial example for the input image. FGSM generates the adversarial perturbation, <inline-formula id="pone.0243963.e001"><alternatives><graphic id="pone.0243963.e001g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e001" xlink:type="simple"/><mml:math display="inline" id="M1"><mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo></mml:mover></mml:math></alternatives></inline-formula>, for <bold><italic>x</italic></bold> using gradient ∇<sub><italic>x</italic></sub><italic>L</italic>(<bold><italic>x</italic></bold>, <italic>y</italic>) of the loss function at the specified image <bold><italic>x</italic></bold> and class <italic>y</italic> with respect to the pixels [<xref ref-type="bibr" rid="pone.0243963.ref021">21</xref>]. For the <italic>L</italic><sub>∞</sub> norm, a non-targeted perturbation that causes misclassification is computed as <inline-formula id="pone.0243963.e002"><alternatives><graphic id="pone.0243963.e002g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e002" xlink:type="simple"/><mml:math display="inline" id="M2"><mml:mrow><mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo>ϵ</mml:mo><mml:mo>⋅</mml:mo><mml:mtext>sign</mml:mtext><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mo>∇</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi></mml:msub><mml:mi>L</mml:mi><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo>(</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></alternatives></inline-formula>), whereas a targeted perturbation that causes <italic>C</italic> classification of an image <bold><italic>x</italic></bold> into class <italic>y</italic> is obtained as <inline-formula id="pone.0243963.e003"><alternatives><graphic id="pone.0243963.e003g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e003" xlink:type="simple"/><mml:math display="inline" id="M3"><mml:mrow><mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo>−</mml:mo><mml:mo>ϵ</mml:mo><mml:mo>⋅</mml:mo><mml:mtext>sign</mml:mtext><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mo>∇</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi></mml:msub><mml:mi>L</mml:mi><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mo>)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></alternatives></inline-formula>, where ϵ (&gt; 0) is the attack strength. For the <italic>L</italic><sub>1</sub> and <italic>L</italic><sub>2</sub> norms, a non-targeted perturbation is computed as <inline-formula id="pone.0243963.e004"><alternatives><graphic id="pone.0243963.e004g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e004" xlink:type="simple"/><mml:math display="inline" id="M4"><mml:mrow> <mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo> </mml:mover> <mml:mo>=</mml:mo><mml:mrow><mml:mrow><mml:mo>ϵ</mml:mo><mml:mo>⋅</mml:mo><mml:msub> <mml:mo>∇</mml:mo> <mml:mi mathvariant="bold-italic">x</mml:mi></mml:msub><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mo>/</mml:mo><mml:mrow><mml:mo>∥</mml:mo><mml:msub> <mml:mo>∇</mml:mo> <mml:mi mathvariant="bold-italic">x</mml:mi></mml:msub><mml:mi>L</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>,</mml:mo><mml:mi>C</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:msub> <mml:mo>∥</mml:mo> <mml:mi>p</mml:mi></mml:msub></mml:mrow></mml:mrow> </mml:mrow></mml:math></alternatives></inline-formula>, whereas a targeted perturbation is obtained as <inline-formula id="pone.0243963.e005"><alternatives><graphic id="pone.0243963.e005g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e005" xlink:type="simple"/><mml:math display="inline" id="M5"><mml:mrow><mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo></mml:mover><mml:mo>=</mml:mo><mml:mo>−</mml:mo><mml:mo>ϵ</mml:mo><mml:mo>⋅</mml:mo><mml:msub><mml:mo>∇</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi></mml:msub><mml:mi>L</mml:mi><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mo>)</mml:mo><mml:mo>/</mml:mo><mml:msub><mml:mrow><mml:mo>∥</mml:mo><mml:mrow><mml:msub><mml:mo>∇</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi></mml:msub><mml:mi>L</mml:mi><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>,</mml:mo><mml:mi>y</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>∥</mml:mo></mml:mrow><mml:mi>p</mml:mi></mml:msub></mml:mrow></mml:math></alternatives></inline-formula>.</p>
<p>In the algorithms, FGSM is performed based on the output <italic>C</italic>(<bold><italic>x</italic></bold> + <bold><italic>ρ</italic></bold>) of the classifier for the perturbed image <bold><italic>x</italic></bold> + <bold><italic>ρ</italic></bold>, at each iteration step. For non-targeted (targeted) attacks, an adversarial perturbation, <inline-formula id="pone.0243963.e006"><alternatives><graphic id="pone.0243963.e006g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e006" xlink:type="simple"/><mml:math display="inline" id="M6"><mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo></mml:mover></mml:math></alternatives></inline-formula>, for <bold><italic>x</italic></bold> + <bold><italic>ρ</italic></bold> is obtained using the FGSM if <italic>C</italic>(<bold><italic>x</italic></bold> + <bold><italic>ρ</italic></bold>) = <italic>C</italic>(<bold><italic>x</italic></bold>) · (<italic>C</italic>(<bold><italic>x</italic></bold> + <bold><italic>ρ</italic></bold>) ≠ <italic>y</italic>). After generating the adversarial example (i.e., <inline-formula id="pone.0243963.e007"><alternatives><graphic id="pone.0243963.e007g" mimetype="image" position="anchor" xlink:href="info:doi/10.1371/journal.pone.0243963.e007" xlink:type="simple"/><mml:math display="inline" id="M7"><mml:mrow><mml:msub><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mrow><mml:mtext>adv</mml:mtext></mml:mrow></mml:msub><mml:mo>←</mml:mo><mml:mi mathvariant="bold-italic">x</mml:mi><mml:mo>+</mml:mo><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>+</mml:mo><mml:mover accent="true"><mml:mi mathvariant="bold-italic">ρ</mml:mi><mml:mo>^</mml:mo></mml:mover></mml:mrow></mml:math></alternatives></inline-formula>) at this step, the perturbation <bold><italic>ρ</italic></bold> is updated if <italic>C</italic>(<bold><italic>x</italic></bold><sub>adv</sub>) ≠ <italic>C</italic>(<bold><italic>x</italic></bold>) (<italic>C</italic>(<bold><italic>x</italic></bold><sub>adv</sub>) = <italic>y</italic>) for non-targeted (targeted) attacks. When updating <bold><italic>ρ</italic></bold>, a projection function project, (<bold><italic>x</italic></bold>, <italic>p</italic>, <italic>ξ</italic>), is used to satisfy the constraint that ‖<bold><italic>ρ</italic></bold>‖<sub><italic>p</italic></sub> ≤ <italic>ξ</italic>: <bold><italic>ρ</italic></bold> ← project(<bold><italic>x</italic></bold><sub>adv</sub> − <bold><italic>x</italic></bold>, <italic>p</italic>, <italic>ξ</italic>), where project(<bold><italic>x</italic></bold>, <italic>p</italic>, <italic>ξ</italic>) = arg min<sub><italic>x</italic>′</sub>‖<bold><italic>x</italic></bold> − <bold><italic>x</italic></bold>′‖<sub>2</sub> subject to ‖<bold><italic>ρ</italic></bold>‖<sub><italic>p</italic></sub> ≤ <italic>ξ</italic>.</p>
<p>The non-targeted and targeted UAPs were generated using 13,569 training images in the COVIDx dataset. Parameter ϵ was set to 0.001; the cases where <italic>p</italic> = 2 and ∞ were considered. Meanwhile, parameter <italic>ξ</italic> was determined based on the ratio <italic>ζ</italic> of the <italic>L</italic><sub><italic>p</italic></sub> norm of the UAP to the average <italic>L</italic><sub><italic>p</italic></sub> norm of an image in the COVIDx dataset. Cases in which <italic>ζ</italic> = 1% and 2% (i.e., almost imperceptible perpetuations) were considered. The average <italic>L</italic><sub>∞</sub> and <italic>L</italic><sub>2</sub> norms were 237 and 32,589, respectively; <italic>i</italic><sub>max</sub> was set to 15.</p>
<p>To compare the performance of the generated UAPs with that of random controls, we also generated random vectors (random UAPs) sampled uniformly from the sphere of a specified radius [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>].</p>
</sec>
<sec id="sec005">
<title>Vulnerability evaluation</title>
<p>To evaluate the vulnerability of the DNN models to UAPs, we used the fooling rate, <italic>R</italic><sub><italic>f</italic></sub>, and targeted the attack success rate, <italic>R</italic><sub><italic>s</italic></sub>, of non-targeted and targeted attacks, respectively. The <italic>R</italic><sub><italic>f</italic></sub> of an image set is defined as the proportion of images that were not classified into their associated actual labels to all images in the set. The <italic>R</italic><sub><italic>s</italic></sub> of an image set is the proportion of adversarial images classified into the target class to all images in the set. Additionally, we obtained the confusion matrices to evaluate the change in prediction owing to the UAPs for each class (infection type).</p>
</sec>
<sec id="sec006">
<title>Adversarial retraining</title>
<p>We performed adversarial retraining to increase the robustness of the COVID-Net models to UAPs [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref027">27</xref>]; in particular, the models were fine-tuned with adversarial images, and the procedure was described in a previous study [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>]. A brief description is provided below. 1) Ten UAPs against a DNN model were generated using the algorithm (for generating a non-targeted or targeted UAP) (see <xref ref-type="sec" rid="sec002">Materials and methods</xref> section) with the (clean) training image set. 2) A modified training image set was obtained by randomly selecting half of the training images and combining them with the rest, where each image was perturbed by a UAP randomly selected from 10 UAPs. 3) The model was fine-tuned by performing five extra epochs of training on the modified training image set. 4) A new UAP (against the fine-tuned model) was generated using the algorithm with the training image set. 5) <italic>R</italic><sub><italic>f</italic></sub> and <italic>R</italic><sub><italic>s</italic></sub> of the UAP for the test images were then computed. Steps 1)–5) were repeated five times.</p>
</sec>
</sec>
<sec id="sec007" sec-type="results">
<title>Results</title>
<sec id="sec008">
<title>Performance of COVID-Net models</title>
<p>The test accuracies of the COVIDNet-CXR Small and COVIDNet-CXR Large models were 92.6% and 94.4%, respectively, and their training accuracies were 95.8% and 94.1%, respectively. As shown in the COVID-Net study [<xref ref-type="bibr" rid="pone.0243963.ref007">7</xref>], we also confirmed that the COVID-Net models achieved good accuracies.</p>
</sec>
<sec id="sec009">
<title>Vulnerability to non-targeted universal adversarial perturbations</title>
<p>However, we found that both COVIDNet-CXR Small and COVIDNet-CXR Large models were vulnerable to non-targeted UAPs (<xref ref-type="table" rid="pone.0243963.t001">Table 1</xref>). Specifically, the fooling rate, <italic>R</italic><sub><italic>f</italic></sub>, of the UAPs with <italic>ζ</italic> = 1% for the test image set was 81.0% at most. A higher <italic>ζ</italic> led to a higher <italic>R</italic><sub><italic>f</italic></sub>. We observed that the <italic>R</italic><sub><italic>f</italic></sub> of the UAP with <italic>ζ</italic> = 2% for the test image set was between 85.7% and 87.4%. Furthermore, the random UAPs with <italic>ζ</italic> = 2% misclassified the models; specifically, their <italic>R</italic><sub><italic>f</italic></sub> were up to 22.1%. The change in <italic>R</italic><sub><italic>f</italic></sub> did not exhibit significant dependence on the norm types (<italic>p</italic> = 2 or ∞). The difference in <italic>R</italic><sub><italic>f</italic></sub> for the test image set between <italic>p</italic> = 2 and <italic>p</italic> = ∞ was up to 7%, the model and the other parameters being equal. <italic>R</italic><sub><italic>f</italic></sub> of the UAP against the COVIDNet-CXR Small model was lower than that of the COVIDNet-CXR Large model in the case of <italic>ζ</italic> = 1%, the model and the other parameters being equal; however, no remarkable difference in <italic>R</italic><sub><italic>f</italic></sub> between these models was observed in the case of <italic>ζ</italic> = 2%. The <italic>R</italic><sub><italic>f</italic></sub> of the training image set was higher than that of the test image set because the UAPs were generated based on the training image set.</p>
<table-wrap id="pone.0243963.t001" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.t001</object-id>
<label>Table 1</label> <caption><title>Fooling rates <italic>R</italic><sub><italic>f</italic></sub> (%) of non-targeted UAPs against the COVID-Net models.</title></caption>
<alternatives>
<graphic id="pone.0243963.t001g" mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.t001" xlink:type="simple"/>
<table>
<colgroup>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2"><italic>p</italic></th>
<th align="left" rowspan="2"><italic>ζ</italic></th>
<th align="center" colspan="2">COVIDNet-CXR Small</th>
<th align="center" colspan="2">COVIDNet-CXR Large</th>
</tr>
<tr>
<th align="center">Training</th>
<th align="center">Test</th>
<th align="center">Training</th>
<th align="center">Test</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="2">2</td>
<td align="center">1%</td>
<td align="center">61.4 (1.3)</td>
<td align="center">58.0 (0.4)</td>
<td align="center">90.0 (2.5)</td>
<td align="center">81.0 (3.9)</td>
</tr>
<tr>
<td align="center">2%</td>
<td align="center">98.5 (12.6)</td>
<td align="center">87.4 (16.0)</td>
<td align="center">97.4 (17.9)</td>
<td align="center">85.7 (22.1)</td>
</tr>
<tr>
<td align="left" rowspan="2">∞</td>
<td align="center">1%</td>
<td align="center">70.8 (1.0)</td>
<td align="center">64.9 (1.3)</td>
<td align="center">84.8 (2.0)</td>
<td align="center">77.1 (3.5)</td>
</tr>
<tr>
<td align="center">2%</td>
<td align="center">98.5 (9.4)</td>
<td align="center">87.4 (13.4)</td>
<td align="center">97.4 (14.3)</td>
<td align="center">85.7 (19.9)</td>
</tr>
</tbody>
</table>
</alternatives>
<table-wrap-foot>
<fn id="t001fn001"><p>The <italic>R</italic><sub><italic>f</italic></sub> of the training and test images are presented. The values in the brackets indicate <italic>R</italic><sub><italic>f</italic></sub> random UAPs (random controls).</p></fn>
</table-wrap-foot>
</table-wrap>
<p>Owing to non-targeted UAPs, the models classified most images into <italic>COVID-19</italic>. <xref ref-type="fig" rid="pone.0243963.g001">Fig 1</xref> shows the confusion matrices for the COVID-Net models attacked using non-targeted UAPs with <italic>p</italic> = ∞. For the UAPs with <italic>ζ</italic> = 1%, the COVIDNet-CXR Small model classified &gt;70% of the <italic>normal</italic> and <italic>pneumonia</italic> test images into <italic>COVID-19</italic>. Moreover, the COVIDNet-CXR Large model classified approximately 90% of the <italic>normal</italic> and <italic>pneumonia</italic> images into <italic>COVID-19</italic>. For a higher <italic>ζ</italic>, this tendency was more significant. In particular, the COVIDNet-CXR Small and Large models evaluated almost all <italic>normal</italic> and <italic>pneumonia</italic> test images as COVID-19 cases when <italic>ζ</italic> = 2%. Additionally, the tendency of adversarial images to be classified into <italic>COVID-19</italic> was observed when considering UAPs with <italic>p</italic> = 2 and the training image set.</p>
<fig id="pone.0243963.g001" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.g001</object-id>
<label>Fig 1</label>
<caption>
<title>Confusion matrices for the COVID-Net models attacked using the non-targeted UAPs on the test images.</title>
<p><italic>p</italic> = ∞. Left and right panels represent the COVIDNet-CXR Small and COVIDNet-CXR Large models, respectively. The top and bottom panels indicate <italic>ζ</italic> = 1% and <italic>ζ</italic> = 2%, respectively.</p>
</caption>
<graphic mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.g001" xlink:type="simple"/>
</fig>
<p>The non-targeted UAPs with <italic>ζ</italic> = 1% and <italic>ζ</italic> = 2% were almost imperceptible. <xref ref-type="fig" rid="pone.0243963.g002">Fig 2</xref> shows the non-targeted UAPs <italic>p</italic> = ∞ against the COVID-Net models and their adversarial images. The models classified the original X-ray images (left panels in <xref ref-type="fig" rid="pone.0243963.g002">Fig 2</xref>) and correctly predicted their actual classes; however, they evaluated all adversarial images as COVID-19 cases owing to the non-targeted UAPs. Similarly, the non-targeted UAPs <italic>p</italic> = 2 were almost imperceptible.</p>
<fig id="pone.0243963.g002" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.g002</object-id>
<label>Fig 2</label>
<caption>
<title>Non-targeted UAPs with <italic>p</italic> = ∞ against the COVID-Net models and their adversarial images.</title>
<p>UAPs (top panels) with <italic>ζ</italic> = 1% and <italic>ζ</italic> = 2% are shown. The models correctly classified the original images (left panels) into their actual labels. The predicted labels of all adversarial images are of <italic>COVID-19</italic>. Note that the UAPs are emphatically displayed for clarity; in particular, each UAP is scaled by a maximum of 1 and a minimum of 0.</p>
</caption>
<graphic mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.g002" xlink:type="simple"/>
</fig>
</sec>
<sec id="sec010">
<title>Vulnerability to targeted universal adversarial perturbations</title>
<p>Furthermore, we found that both the COVIDNet-CXR Small model (<xref ref-type="table" rid="pone.0243963.t002">Table 2</xref>) and COVIDNet-CXR Large model (<xref ref-type="table" rid="pone.0243963.t003">Table 3</xref>) were vulnerable to targeted UAPs. Subsequently, we considered the effect of the targeted attacks using UAPs in each class: <italic>normal</italic>, <italic>pneumonia</italic>, and <italic>COVID-19</italic>. When <italic>ζ</italic> = 1%, the targeted attack success rates <italic>R</italic><sub><italic>s</italic></sub> for the test images were between approximately 60% and 85% and between approximately 55% and 95% for the COVIDNet-CXR Small and Large models, respectively. Conversely, the <italic>R</italic><sub><italic>s</italic></sub> of the training images was between approximately 65% and 90% and between approximately 55% and 90%. Meanwhile, the <italic>R</italic><sub><italic>s</italic></sub> of the UAP with <italic>p</italic> = 2 was higher than that of the UAP with <italic>p</italic> = ∞, the model, and the other parameters being equal. Moreover, no remarkable difference in the <italic>R</italic><sub><italic>s</italic></sub> was observed between the target classes; however, the <italic>R</italic><sub><italic>s</italic></sub> of the target attacks to <italic>COVID-19</italic> were relatively high in the COVIDNet-CXR Large model. Thus, a higher <italic>ζ</italic> led to a higher <italic>R</italic><sub><italic>s</italic></sub>. When <italic>ζ</italic> = 2%, the <italic>R</italic><sub><italic>s</italic></sub> values for both the training and test images were approximately 100%, regardless of the target classes. For the targeted attacks to <italic>normal</italic> and <italic>pneumonia</italic>, the <italic>R</italic><sub><italic>s</italic></sub> of random UAPs for the test images were also relatively high; in particular, they were between approximately 35% and 45% and between approximately 30% and 45% for the COVIDNet-CXR Small model and COVIDNet-CXR Large model, respectively.</p>
<table-wrap id="pone.0243963.t002" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.t002</object-id>
<label>Table 2</label> <caption><title>Targeted attack success rate <italic>R</italic><sub><italic>s</italic></sub> (%) of targeted UAPs against the COVIDNet-CXR Small model to each target class.</title></caption>
<alternatives>
<graphic id="pone.0243963.t002g" mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.t002" xlink:type="simple"/>
<table>
<colgroup>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2"><italic>p</italic></th>
<th align="left" rowspan="2"><italic>ζ</italic></th>
<th align="center" colspan="2"><italic>Normal</italic></th>
<th align="center" colspan="2"><italic>Pneumonia</italic></th>
<th align="center" colspan="2"><italic>COVID-19</italic></th>
</tr>
<tr>
<th align="center">Training</th>
<th align="center">Test</th>
<th align="center">Training</th>
<th align="center">Test</th>
<th align="center">Training</th>
<th align="center">Test</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="2">2</td>
<td align="center">1%</td>
<td align="center">88.1 (60.5)</td>
<td align="center">78.4 (46.3)</td>
<td align="center">76.7 (37.5)</td>
<td align="center">71.4 (41.6)</td>
<td align="center">68.1 (1.9)</td>
<td align="center">74.0 (12.1)</td>
</tr>
<tr>
<td align="center">2%</td>
<td align="center">99.4 (54.4)</td>
<td align="center">97.8 (39.0)</td>
<td align="center">99.4 (33.0)</td>
<td align="center">98.7 (35.9)</td>
<td align="center">100 (12.6)</td>
<td align="center">99.1 (25.1)</td>
</tr>
<tr>
<td align="left" rowspan="2">∞</td>
<td align="center">1%</td>
<td align="center">79.5 (60.7)</td>
<td align="center">64.9 (45.9)</td>
<td align="center">66.5 (37.5)</td>
<td align="center">61.9 (41.6)</td>
<td align="center">78.8 (1.8)</td>
<td align="center">84.0 (12.6)</td>
</tr>
<tr>
<td align="center">2%</td>
<td align="center">98.7 (56.3)</td>
<td align="center">96.1 (39.4)</td>
<td align="center">99.5 (34.1)</td>
<td align="center">98.3 (37.7)</td>
<td align="center">100 (9.5)</td>
<td align="center">100 (22.9)</td>
</tr>
</tbody>
</table>
</alternatives>
<table-wrap-foot>
<fn id="t002fn001"><p>The <italic>R</italic><sub><italic>s</italic></sub> for the training and test images are shown in Table 2. The values in brackets are <italic>R</italic><sub><italic>s</italic></sub> random UAPs (random controls).</p></fn>
</table-wrap-foot>
</table-wrap>
<table-wrap id="pone.0243963.t003" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.t003</object-id>
<label>Table 3</label> <caption><title>Targeted attack success rates <italic>R</italic><sub><italic>s</italic></sub> (%) of targeted UAPs against the COVIDNet-CXR Large model to each target class.</title></caption>
<alternatives>
<graphic id="pone.0243963.t003g" mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.t003" xlink:type="simple"/>
<table>
<colgroup>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
<col align="left" valign="middle"/>
</colgroup>
<thead>
<tr>
<th align="left" rowspan="2"><italic>p</italic></th>
<th align="left" rowspan="2"><italic>ζ</italic></th>
<th align="center" colspan="2"><italic>Normal</italic></th>
<th align="center" colspan="2"><italic>Pneumonia</italic></th>
<th align="center" colspan="2"><italic>COVID-19</italic></th>
</tr>
<tr>
<th align="center">Training</th>
<th align="center">Test</th>
<th align="center">Training</th>
<th align="center">Test</th>
<th align="center">Training</th>
<th align="center">Test</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" rowspan="2">2</td>
<td align="center">1%</td>
<td align="center">85.2 (58.9)</td>
<td align="center">71.4 (44.2)</td>
<td align="center">72.6 (37.0)</td>
<td align="center">66.2 (39.0)</td>
<td align="center">92.4 (4.0)</td>
<td align="center">95.2 (16.9)</td>
</tr>
<tr>
<td align="center">2%</td>
<td align="center">99.2 (50.7)</td>
<td align="center">98.3 (34.6)</td>
<td align="center">99.5 (30.6)</td>
<td align="center">98.7 (32.9)</td>
<td align="center">100 (18.7)</td>
<td align="center">100 (32.5)</td>
</tr>
<tr>
<td align="left" rowspan="2">∞</td>
<td align="center">1%</td>
<td align="center">71.0 (59.2)</td>
<td align="center">56.7 (44.2)</td>
<td align="center">55.4 (37.0)</td>
<td align="center">53.2 (40.3)</td>
<td align="center">88.4 (3.7)</td>
<td align="center">92.2 (15.6)</td>
</tr>
<tr>
<td align="center">2%</td>
<td align="center">97.9 (52.7)</td>
<td align="center">93.9 (35.9)</td>
<td align="center">99.4 (32.3)</td>
<td align="center">98.3 (33.8)</td>
<td align="center">100 (14.9)</td>
<td align="center">100 (30.3)</td>
</tr>
</tbody>
</table>
</alternatives>
<table-wrap-foot>
<fn id="t003fn001"><p>The <italic>R</italic><sub><italic>s</italic></sub> for the training and test images are shown in Table 3. The values in brackets are <italic>R</italic><sub><italic>s</italic></sub> random UAPs (random controls).</p></fn>
</table-wrap-foot>
</table-wrap>
<p>It was difficult to classify the <italic>COVID-19</italic> images into another targeted class (<italic>normal</italic> or <italic>pneumonia</italic>) when the UAPs were relatively weak (i.e., <italic>ζ</italic> = 1%). <xref ref-type="fig" rid="pone.0243963.g003">Fig 3</xref> shows the confusion matrices for the COVIDNet-CXR Small model attacked using targeted UAPs with <italic>p</italic> = ∞. For both targeted attacks to <italic>normal</italic> and <italic>pneumonia</italic>, the model correctly predicted almost all <italic>COVID-19</italic> images as COVID-19 cases, despite the targeted attacks. Conversely, approximately 50% of <italic>normal</italic> (<italic>pneumonia</italic>) images were classified as targeted class <italic>pneumonia</italic> (<italic>normal</italic>). However, for a higher <italic>ζ</italic> (i.e., <italic>ζ</italic> = 2%), the targeted attacks of the <italic>COVID-19</italic> images were successful; in particular, almost all <italic>COVID-19</italic> images were classified into the target class (<italic>normal</italic> or <italic>pneumonia</italic>) because of the UAP. The classification of the images into COVID-19 using targeted UAPs was easier than that into the other classes. Owing to the UAP with <italic>ζ</italic> = 1%, the model judged approximately 80% of <italic>normal</italic> and <italic>pneumonia</italic> images as COVID-19 cases, respectively. Similar tendencies were observed in the COVIDNet-CXR Large model for targeted UAPs with <italic>p</italic> = 2 and on the training image set.</p>
<fig id="pone.0243963.g003" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.g003</object-id>
<label>Fig 3</label>
<caption>
<title>Confusion matrices for the COVIDNet-CXR Small model attacked with the targeted UAPs with <italic>p</italic> = ∞ on the test images.</title>
<p>The left, middle, and right panels represent the targeted classes: <italic>normal</italic>, <italic>pneumonia</italic>, and <italic>COVID-19</italic>, respectively. The top and bottom panels indicate <italic>ζ</italic> = 1% and <italic>ζ</italic> = 2%, respectively.</p>
</caption>
<graphic mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.g003" xlink:type="simple"/>
</fig>
<p>The targeted UAPs were also almost imperceptible. <xref ref-type="fig" rid="pone.0243963.g004">Fig 4</xref> shows the targeted UAPs with <italic>p</italic> = ∞ and <italic>ζ</italic> = 2% against the COVIDNet-CXR Small model and their adversarial images. The model classified the original images (left panels in <xref ref-type="fig" rid="pone.0243963.g004">Fig 4</xref>) and correctly predicted their actual classes (source classes); however, it classified the adversarial images into each target class because of the targeted UAPs. The UAPs with <italic>ζ</italic> = 1% were also imperceptible. Additionally, imperceptibility was confirmed in the UAPs with <italic>p</italic> = 2 and those against the COVIDNet-CXR Large model.</p>
<fig id="pone.0243963.g004" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.g004</object-id>
<label>Fig 4</label>
<caption>
<title>Targeted UAPs (top panel) with <italic>ζ</italic> = 2% and <italic>p</italic> = ∞ against the COVIDNet-CXR Small model and their adversarial images.</title>
<p>Note that UAPs are emphatically displayed for clarity; in particular, each UAP is scaled by a maximum of 1 and a minimum of 0.</p>
</caption>
<graphic mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.g004" xlink:type="simple"/>
</fig>
</sec>
<sec id="sec011">
<title>Effect of adversarial retraining</title>
<p>Adversarial retraining is often used to avoid adversarial attacks. In this study, we investigated the extent to which adversarial retraining increases the robustness of the COVIDNet-CXR Small model to non-targeted and targeted UAPs with <italic>p</italic> = ∞. Adversarial retraining did not affect the test accuracy in either non-targeted or targeted cases; specifically, the accuracy on the (clean) test images remained constant at approximately 90% (<xref ref-type="fig" rid="pone.0243963.g005">Fig 5A and 5B</xref>).</p>
<fig id="pone.0243963.g005" position="float">
<object-id pub-id-type="doi">10.1371/journal.pone.0243963.g005</object-id>
<label>Fig 5</label>
<caption>
<title>Effect of adversarial retraining on the robustness to UAPs with <italic>p</italic> = ∞ against the COVIDNet-CXR Small model.</title>
<p>Scatter plots of (A) the fooling rate, <italic>R</italic><sub><italic>f</italic></sub> (%), for non-targeted UAPs with <italic>ζ</italic> = 2% versus the number, <italic>N</italic><sub><italic>i</italic></sub>, of iterations for adversarial retraining and (B) the targeted attack success rate, <italic>R</italic><sub><italic>s</italic></sub> (%), of targeted UAPs with <italic>ζ</italic> = 1% to <italic>COVID-19</italic> versus <italic>N</italic><sub><italic>i</italic></sub>. Here, <italic>R</italic><sub><italic>f</italic></sub> and <italic>R</italic><sub><italic>s</italic></sub> are for the test images. The accuracies (%) on the set of clean test images are also shown. The confusion matrices for the fine-tuned models were obtained after five iterations of adversarial retraining using the (C) non-targeted UAPs and (D) targeted UAPs. Note that these confusion matrices belong to the fine-tuned models attacked using non-targeted and targeted UAPs, respectively.</p>
</caption>
<graphic mimetype="image" position="float" xlink:href="info:doi/10.1371/journal.pone.0243963.g005" xlink:type="simple"/>
</fig>
<p>For non-targeted attacks using UAPs with <italic>ζ</italic> = 2%, <italic>R</italic><sub><italic>f</italic></sub> for the test images declined with the iterations for adversarial retraining; in particular, it was 22.1% after five iterations (<xref ref-type="fig" rid="pone.0243963.g005">Fig 5A</xref>). The confusion matrix (<xref ref-type="fig" rid="pone.0243963.g005">Fig 5C</xref>) for the fine-tuned model obtained after five iterations indicates that the <italic>normal</italic> and <italic>COVID-19</italic> images were almost correctly classified despite the non-targeted UAPs. However, 45% of the <italic>pneumonia</italic> images were still misclassified.</p>
<p>For targeted attacks to <italic>COVID-19</italic> using UAPs with <italic>ζ</italic> = 1%, the <italic>R</italic><sub><italic>s</italic></sub> for the test images decreased with the iterations for adversarial retraining (<xref ref-type="fig" rid="pone.0243963.g005">Fig 5B</xref>); specifically, it was 16.5% after five iterations. The confusion matrix (<xref ref-type="fig" rid="pone.0243963.g005">Fig 5D</xref>) for the fine-tuned model obtained after five iterations indicates that the <italic>normal</italic> and <italic>COVID-19</italic> images were almost correctly classified despite the targeted UAPs. However, 15% of the <italic>pneumonia</italic> images were still misclassified as <italic>COVID-19</italic>.</p>
</sec>
</sec>
<sec id="sec012" sec-type="conclusions">
<title>Discussion</title>
<p>The COVID-Net models were vulnerable to small UAPs; moreover, they were slightly less robust to random UAPs. The results indicated that the DNN-based systems were easy to mislead. Adversaries can result in failing the DNN-based systems at lower costs (i.e., using a single perturbation); specifically, they do not need to consider the distribution and diversity of input images when attacking the DNNs using UAPs, as UPAs are image agnostic. Considering that vulnerability to UAPs is observed in various DNN architectures [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref024">24</xref>], they are expected to exist universally in DNN-based systems for detecting COVID-19 cases.</p>
<p>For non-targeted attacks with UAPs, the COVID-Net models predicted most of the chest X-ray images as COVID-19 cases because of the UAPs (<xref ref-type="fig" rid="pone.0243963.g001">Fig 1</xref>), although the UAPs were almost imperceptible (<xref ref-type="fig" rid="pone.0243963.g002">Fig 2</xref>). This result is consistent with the tendency of DNN models to classify most inputs into a few specific classes because of non-targeted UAPs (i.e., existence of dominant labels in non-targeted attacks based on UAPs) [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>]. Moreover, this indicates that the models provide false positives in COVID-19 diagnosis, which may cause unwanted mental stress to patients and complicate the estimation of the number of COVID-19 cases. The dominant label of COVID-19 observed in this study may be because the COVIDx dataset was imbalanced. The images in <italic>COVID-19</italic> were predominantly fewer than those in <italic>normal</italic> and <italic>pneumonia</italic> cases. The algorithm considers maximizing the fooling rate; thus, a relatively large fooling rate is achieved when all inputs are classified into <italic>COVID-19</italic> because of UAPs. In addition, the observed dominant label may be because the losses were computed by weighting the <italic>COVID-19</italic> class to consider the imbalanced dataset. The decision for the <italic>COVID-19</italic> class might be more susceptible to changes in pixel values than that for the other classes.</p>
<p>The relatively easy targeted attacks on <italic>COVID-19</italic> (<xref ref-type="fig" rid="pone.0243963.g003">Fig 3</xref>) may be because <italic>COVID-19</italic> was the dominant label. Moreover, targeted attacks to <italic>normal</italic> and <italic>pneumonia</italic> were possible, despite almost imperceptible UAPs (<xref ref-type="fig" rid="pone.0243963.g004">Fig 4</xref>). The results imply that adversaries can control DNN-based systems, which may lead to security concerns. The targeted attacks cause both false positives and negatives, and thus, can be used to adjust the number of COVID-19 cases. Moreover, they may affect individual and social awareness of COVID-19 (e.g., voluntary restraint and social distancing). These may lead to problems in terms of public health (i.e., minimizing the spread of the pandemic) and the economy. More generally, complex classifiers, including DNNs, are currently used for high-stake decision making in healthcare; however, they can potentially cause catastrophic harm to the society because they are often difficult to interpret [<xref ref-type="bibr" rid="pone.0243963.ref031">31</xref>].</p>
<p>The COVID-Net models, with tailored network architecture, seem to be more vulnerable to adversarial attacks than representative DNN models (e.g., VGG [<xref ref-type="bibr" rid="pone.0243963.ref032">32</xref>] and ResNet [<xref ref-type="bibr" rid="pone.0243963.ref033">33</xref>] models) for classifying ideal natural images (e.g., CIFAR-10 [<xref ref-type="bibr" rid="pone.0243963.ref034">34</xref>] and ImageNet datasets [<xref ref-type="bibr" rid="pone.0243963.ref035">35</xref>]). For these representative DNNs, UAPs with <italic>ζ</italic> = 5% and higher are required to achieve &gt;80% success rates for non-targeted and targeted attacks [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref028">28</xref>]. Conversely, for the COVID-Net models, UAPs with <italic>ζ</italic> = 2% achieved &gt;85% and &gt;90% success rates for the non-targeted and targeted attacks, respectively. This result implies several possible reasons that caused the vulnerability of COVID-Net models. For example, the variance (visual difference) in chest X-ray images is much less than that in natural images. In this case, data points may aggregate around decision boundaries, indicating that the outputs of the DNN models are susceptible to changes in pixel values. As a result, adversarial examples are easy to generate. In addition, the fact that adversarial vulnerability of DNNs is known to increase with input dimension [<xref ref-type="bibr" rid="pone.0243963.ref036">36</xref>] may be one of the causes.</p>
<p>The UAPs used in this study are a type of white-box attack, which assumes that adversaries can access the model parameters (the gradient of the loss function, in this case) and training images; thus, they are security threats for open-source software projects, such as COVID-Net. A simple solution to prevent these adversarial attacks is to make DNN-based systems closed-source and publicly unavailable; however, this conflicts with the purpose of accelerating the development of computer-based systems for detecting COVID-19 cases and COVID-19 treatment. An alternative may be to consider black-box systems, such as closed application programming interfaces (APIs) and closed-source software in which only queries on inputs are allowed and outputs are accessible. Such closed APIs are better because they are at least publicly available. However, it is possible that APIs are vulnerable to adversarial attacks. This is because UAPs have generalizability [<xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>] (i.e., UAPs for a DNN can mislead another DNN). That is, adversarial attacks on black-box DNN-based systems may be possible using the UAPs generated based on white-box DNNs. Moreover, several methods for adversarial attacks on black-box DNN-based systems, which estimate adversarial perturbations using only model outputs (e.g., confidence scores), have been proposed [<xref ref-type="bibr" rid="pone.0243963.ref037">37</xref>–<xref ref-type="bibr" rid="pone.0243963.ref039">39</xref>].</p>
<p>Therefore, defense strategies against adversarial attacks should be considered. A simple defense strategy is to fine-tune DNN models using adversarial images [<xref ref-type="bibr" rid="pone.0243963.ref022">22</xref>, <xref ref-type="bibr" rid="pone.0243963.ref023">23</xref>, <xref ref-type="bibr" rid="pone.0243963.ref027">27</xref>]. In fact, we demonstrated that iterative fine-tuning of a DNN model using UAPs improved the robustness of the DNN model to non-targeted and targeted UAPs (<xref ref-type="fig" rid="pone.0243963.g005">Fig 5</xref>). However, the iterative fine-tuning method required high computational costs, and it did not perfectly avoid vulnerability to UAPs. In addition, several methods breaching defenses using adversarial retraining have already been proposed [<xref ref-type="bibr" rid="pone.0243963.ref027">27</xref>]. Alternatively, dimensionality reduction (e.g., principle component analysis), distributional detection (e.g., maximum mean discrepancy), and normalization detection (e.g., dropout randomization) may be useful for adversarial defenses; however, adversarial examples are not easily detected using these approaches [<xref ref-type="bibr" rid="pone.0243963.ref027">27</xref>]. Defending against adversarial attacks is a cat-and-mouse game [<xref ref-type="bibr" rid="pone.0243963.ref026">26</xref>]; thus, it may be difficult to completely avoid security concerns caused by adversarial attacks. However, the development of methods for defending against adversarial attacks has advanced. For example, detecting adversarial attack-based robustness to random noise [<xref ref-type="bibr" rid="pone.0243963.ref040">40</xref>], the use of a discontinuous activation function that purposely invalidates the DNN’s gradient at densely distributed input data points [<xref ref-type="bibr" rid="pone.0243963.ref041">41</xref>], and DNNs for purifying adversarial examples [<xref ref-type="bibr" rid="pone.0243963.ref042">42</xref>] may help reduce the concerns.</p>
<p>In conclusion, we demonstrated the vulnerability of DNNs for detecting COVID-19 cases to non-targeted and targeted attacks based on UAPs. However, many studies have developed DNN-based systems for detecting COVID-19 while ignoring the vulnerability. Our findings emphasize that careful consideration is required in developing DNN-based systems for detecting COVID-19 cases and their practical applications. Facile applications of DNNs to COVID-19 detection could lead to problems in terms of public health and the economy. Our study is the first to show the vulnerability of DNNs for COVID-19 detection and to alert such facile applications of DNNs. The code used in this study is available from our GitHub repository: github.com/hkthirano/UAP-COVID-Net. The chest X-ray images used in this study are publicly available online (see github.com/lindawangg/COVID-Net/blob/master/docs/COVIDx.md for details).</p>
</sec>
</body>
<back>
<ack>
<p>The authors are much obliged to Dr. Seyed-Mohsen Moosavi-Dezfooli for his helpful comments regarding the fine-tuning of DNN models with UAPs. The authors would like to thank Editage (<ext-link ext-link-type="uri" xlink:href="http://www.editage.com" xlink:type="simple">www.editage.com</ext-link>) for English language editing.</p>
</ack>
<ref-list>
<title>References</title>
<ref id="pone.0243963.ref001"><label>1</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Dong</surname> <given-names>E</given-names></name>, <name name-style="western"><surname>Du</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Gardner</surname> <given-names>L</given-names></name>. <article-title>An interactive web-based dashboard to track COVID-19 in real time</article-title>. <source>Lancet Infect Dis</source>. <year>2020</year>; <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/S1473-3099(20)30120-1" xlink:type="simple">10.1016/S1473-3099(20)30120-1</ext-link></comment> <object-id pub-id-type="pmid">32087114</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref002"><label>2</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Huang</surname> <given-names>C</given-names></name>, <name name-style="western"><surname>Wang</surname> <given-names>Y</given-names></name>, <name name-style="western"><surname>Li</surname> <given-names>X</given-names></name>, <name name-style="western"><surname>Ren</surname> <given-names>L</given-names></name>, <name name-style="western"><surname>Zhao</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Hu</surname> <given-names>Y</given-names></name>, <etal>et al</etal>. <article-title>Clinical features of patients infected with 2019 novel coronavirus in Wuhan, China</article-title>. <source>Lancet</source>. <year>2020</year>;<volume>395</volume>: <fpage>497</fpage>–<lpage>506</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/S0140-6736(20)30183-5" xlink:type="simple">10.1016/S0140-6736(20)30183-5</ext-link></comment> <object-id pub-id-type="pmid">31986264</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref003"><label>3</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Ahmed</surname> <given-names>F</given-names></name>, <name name-style="western"><surname>Ahmed</surname> <given-names>N</given-names></name>, <name name-style="western"><surname>Pissarides</surname> <given-names>C</given-names></name>, <name name-style="western"><surname>Stiglitz</surname> <given-names>J</given-names></name>. <article-title>Why inequality could spread COVID-19</article-title>. <source>Lancet Public Heal</source>. <year>2020</year>; <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/S2468-2667(20)30085-2" xlink:type="simple">10.1016/S2468-2667(20)30085-2</ext-link></comment> <object-id pub-id-type="pmid">32247329</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref004"><label>4</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Wang</surname> <given-names>D</given-names></name>, <name name-style="western"><surname>Hu</surname> <given-names>B</given-names></name>, <name name-style="western"><surname>Hu</surname> <given-names>C</given-names></name>, <name name-style="western"><surname>Zhu</surname> <given-names>F</given-names></name>, <name name-style="western"><surname>Liu</surname> <given-names>X</given-names></name>, <name name-style="western"><surname>Zhang</surname> <given-names>J</given-names></name>, <etal>et al</etal>. <article-title>Clinical characteristics of 138 hospitalized patients with 2019 novel coronavirus–infected pneumonia in Wuhan, China</article-title>. <source>JAMA</source>. <year>2020</year>;<volume>323</volume>: <fpage>1061</fpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1001/jama.2020.1585" xlink:type="simple">10.1001/jama.2020.1585</ext-link></comment> <object-id pub-id-type="pmid">32031570</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref005"><label>5</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Fang</surname> <given-names>Y</given-names></name>, <name name-style="western"><surname>Zhang</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Xie</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Lin</surname> <given-names>M</given-names></name>, <name name-style="western"><surname>Ying</surname> <given-names>L</given-names></name>, <name name-style="western"><surname>Pang</surname> <given-names>P</given-names></name>, <etal>et al</etal>. <article-title>Sensitivity of chest CT for COVID-19: comparison to RT-PCR</article-title>. <source>Radiology</source>. <year>2020</year>; 200432. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1148/radiol.2020200432" xlink:type="simple">10.1148/radiol.2020200432</ext-link></comment> <object-id pub-id-type="pmid">32073353</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref006"><label>6</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Ng</surname> <given-names>M-Y</given-names></name>, <name name-style="western"><surname>Lee</surname> <given-names>EY</given-names></name>, <name name-style="western"><surname>Yang</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Yang</surname> <given-names>F</given-names></name>, <name name-style="western"><surname>Li</surname> <given-names>X</given-names></name>, <name name-style="western"><surname>Wang</surname> <given-names>H</given-names></name>, <etal>et al</etal>. <article-title>Imaging profile of the COVID-19 infection: radiologic findings and literature review</article-title>. <source>Radiol Cardiothorac Imaging</source>. <year>2020</year>;<volume>2</volume>: <fpage>e200034</fpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1148/ryct.2020200034" xlink:type="simple">10.1148/ryct.2020200034</ext-link></comment></mixed-citation></ref>
<ref id="pone.0243963.ref007"><label>7</label><mixed-citation publication-type="other" xlink:type="simple">Wang L, Wong A. COVID-Net: a tailored deep convolutional neural network design for detection of COVID-19 cases from chest X-Ray images. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2003.09871" xlink:type="simple">http://arxiv.org/abs/2003.09871</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref008"><label>8</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Zhang</surname> <given-names>K</given-names></name>, <name name-style="western"><surname>Liu</surname> <given-names>X</given-names></name>, <name name-style="western"><surname>Shen</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Li</surname> <given-names>Z</given-names></name>, <name name-style="western"><surname>Sang</surname> <given-names>Y</given-names></name>, <name name-style="western"><surname>Wu</surname> <given-names>X</given-names></name>, <etal>et al</etal>. <article-title>Clinically applicable AI system for accurate diagnosis, quantitative measurements and prognosis of COVID-19 pneumonia using computed tomography</article-title>. <source>Cell</source>. <year>2020</year>; <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cell.2020.04.045" xlink:type="simple">10.1016/j.cell.2020.04.045</ext-link></comment> <object-id pub-id-type="pmid">32416069</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref009"><label>9</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Litjens</surname> <given-names>G</given-names></name>, <name name-style="western"><surname>Kooi</surname> <given-names>T</given-names></name>, <name name-style="western"><surname>Bejnordi</surname> <given-names>BE</given-names></name>, <name name-style="western"><surname>Setio</surname> <given-names>AAA</given-names></name>, <name name-style="western"><surname>Ciompi</surname> <given-names>F</given-names></name>, <name name-style="western"><surname>Ghafoorian</surname> <given-names>M</given-names></name>, <etal>et al</etal>. <article-title>A survey on deep learning in medical image analysis</article-title>. <source>Med Image Anal. Elsevier B.V.</source>; <year>2017</year>;<volume>42</volume>: <fpage>60</fpage>–<lpage>88</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.media.2017.07.005" xlink:type="simple">10.1016/j.media.2017.07.005</ext-link></comment> <object-id pub-id-type="pmid">28778026</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref010"><label>10</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Liu</surname> <given-names>X</given-names></name>, <name name-style="western"><surname>Faes</surname> <given-names>L</given-names></name>, <name name-style="western"><surname>Kale</surname> <given-names>AU</given-names></name>, <name name-style="western"><surname>Wagner</surname> <given-names>SK</given-names></name>, <name name-style="western"><surname>Fu</surname> <given-names>DJ</given-names></name>, <name name-style="western"><surname>Bruynseels</surname> <given-names>A</given-names></name>, <etal>et al</etal>. <article-title>A comparison of deep learning performance against health-care professionals in detecting diseases from medical imaging: a systematic review and meta-analysis</article-title>. <source>Lancet Digit Heal. The Author(s). Published by Elsevier Ltd. This is an Open Access article under the CC BY 4.0 license</source>; <year>2019</year>;<volume>1</volume>: <fpage>e271</fpage>–<lpage>e297</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/S2589-7500(19)30123-2" xlink:type="simple">10.1016/S2589-7500(19)30123-2</ext-link></comment></mixed-citation></ref>
<ref id="pone.0243963.ref011"><label>11</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Kermany</surname> <given-names>DS</given-names></name>, <name name-style="western"><surname>Goldbaum</surname> <given-names>M</given-names></name>, <name name-style="western"><surname>Cai</surname> <given-names>W</given-names></name>, <name name-style="western"><surname>Valentim</surname> <given-names>CCS</given-names></name>, <name name-style="western"><surname>Liang</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Baxter</surname> <given-names>SL</given-names></name>, <etal>et al</etal>. <article-title>Identifying Medical Diagnoses and Treatable Diseases by Image-Based Deep Learning</article-title>. <source>Cell. Elsevier Inc.</source>; <year>2018</year>;<volume>172</volume>: <fpage>1122</fpage>–<lpage>1131.e9</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cell.2018.02.010" xlink:type="simple">10.1016/j.cell.2018.02.010</ext-link></comment> <object-id pub-id-type="pmid">29474911</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref012"><label>12</label><mixed-citation publication-type="other" xlink:type="simple">Zhao J, Zhang Y, He X, Xie P. COVID-CT-Dataset: a CT scan dataset about COVID-19. 2020; 2003.13865</mixed-citation></ref>
<ref id="pone.0243963.ref013"><label>13</label><mixed-citation publication-type="other" xlink:type="simple">Cohen JP, Morrison P, Dao L. COVID-19 image data collection. 2020; 2003.11597</mixed-citation></ref>
<ref id="pone.0243963.ref014"><label>14</label><mixed-citation publication-type="other" xlink:type="simple">Zhang J, Xie Y, Li Y, Shen C, Xia Y. COVID-19 screening on chest X-ray images using deep learning based anomaly detection. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2003.12338" xlink:type="simple">http://arxiv.org/abs/2003.12338</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref015"><label>15</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Wang</surname> <given-names>L</given-names></name>, <name name-style="western"><surname>Lin</surname> <given-names>ZQ</given-names></name>, <name name-style="western"><surname>Wong</surname> <given-names>A</given-names></name>. <article-title>COVID-Net: a tailored deep convolutional neural network design for detection of COVID-19 cases from chest X-ray images</article-title>. <source>Sci Rep</source>. <year>2020</year>;<volume>10</volume>: <fpage>19549</fpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1038/s41598-020-76550-z" xlink:type="simple">10.1038/s41598-020-76550-z</ext-link></comment> <object-id pub-id-type="pmid">33177550</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref016"><label>16</label><mixed-citation publication-type="other" xlink:type="simple">Tartaglione E, Barbano CA, Berzovini C, Calandri M, Grangetto M. Unveiling COVID-19 from chest X-ray with deep learning: a hurdles race with small data. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2004.05405" xlink:type="simple">http://arxiv.org/abs/2004.05405</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref017"><label>17</label><mixed-citation publication-type="other" xlink:type="simple">Lv D, Qi W, Li Y, Sun L, Wang Y. A cascade network for detecting COVID-19 using chest X-rays. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2005.01468" xlink:type="simple">http://arxiv.org/abs/2005.01468</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref018"><label>18</label><mixed-citation publication-type="other" xlink:type="simple">Farooq M, Hafeez A. COVID-ResNet: a deep learning framework for screening of COVID19 from radiographs. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2003.14395" xlink:type="simple">http://arxiv.org/abs/2003.14395</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref019"><label>19</label><mixed-citation publication-type="other" xlink:type="simple">Afshar P, Heidarian S, Naderkhani F, Oikonomou A, Plataniotis KN, Mohammadi A. COVID-CAPS: a capsule network-based framework for identification of COVID-19 cases from X-ray Images. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2004.02696" xlink:type="simple">http://arxiv.org/abs/2004.02696</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref020"><label>20</label><mixed-citation publication-type="other" xlink:type="simple">Rahimzadeh M, Attar A. A new modified deep convolutional neural network for detecting COVID-19 from X-ray images. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/2004.08052" xlink:type="simple">http://arxiv.org/abs/2004.08052</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref021"><label>21</label><mixed-citation publication-type="other" xlink:type="simple">Goodfellow IJ, Shlens J, Szegedy C. Explaining and harnessing adversarial examples. 2014; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/1412.6572" xlink:type="simple">http://arxiv.org/abs/1412.6572</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref022"><label>22</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Yuan</surname> <given-names>X</given-names></name>, <name name-style="western"><surname>He</surname> <given-names>P</given-names></name>, <name name-style="western"><surname>Zhu</surname> <given-names>Q</given-names></name>, <name name-style="western"><surname>Li</surname> <given-names>X</given-names></name>. <article-title>Adversarial examples: attacks and defenses for deep learning</article-title>. <source>IEEE Trans Neural Networks Learn Syst</source>. <year>2019</year>;<volume>30</volume>: <fpage>2805</fpage>–<lpage>2824</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/TNNLS.2018.2886017" xlink:type="simple">10.1109/TNNLS.2018.2886017</ext-link></comment> <object-id pub-id-type="pmid">30640631</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref023"><label>23</label><mixed-citation publication-type="other" xlink:type="simple">Moosavi-Dezfooli SM, Fawzi A, Fawzi O, Frossard P. Universal adversarial perturbations. Proc—30th IEEE Conf Comput Vis Pattern Recognition, CVPR 2017. 2017;2017-Janua: 86–94. 10.1109/CVPR.2017.17</mixed-citation></ref>
<ref id="pone.0243963.ref024"><label>24</label><mixed-citation publication-type="other" xlink:type="simple">Hirano H, Takemoto K. Simple iterative method for generating targeted universal adversarial perturbations. Proceedings of 25th International Symposium on Artificial Life and Robotics. 2020. pp. 426–430. <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/1911.06502" xlink:type="simple">http://arxiv.org/abs/1911.06502</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref025"><label>25</label><mixed-citation publication-type="other" xlink:type="simple">Matyasko A, Chau L-P. Improved network robustness with adversary critic. 2018; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/1810.12576" xlink:type="simple">http://arxiv.org/abs/1810.12576</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref026"><label>26</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Finlayson</surname> <given-names>SG</given-names></name>, <name name-style="western"><surname>Bowers</surname> <given-names>JD</given-names></name>, <name name-style="western"><surname>Ito</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Zittrain</surname> <given-names>JL</given-names></name>, <name name-style="western"><surname>Beam</surname> <given-names>AL</given-names></name>, <name name-style="western"><surname>Kohane</surname> <given-names>IS</given-names></name>. <article-title>Adversarial attacks on medical machine learning</article-title>. <source>Science (80-)</source>. <year>2019</year>;<volume>363</volume>: <fpage>1287</fpage>–<lpage>1289</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1126/science.aaw4399" xlink:type="simple">10.1126/science.aaw4399</ext-link></comment> <object-id pub-id-type="pmid">30898923</object-id></mixed-citation></ref>
<ref id="pone.0243963.ref027"><label>27</label><mixed-citation publication-type="other" xlink:type="simple">Carlini N, Wagner D. Adversarial examples are not easily detected. Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security—AISec ‘17. New York, New York, USA: ACM Press; 2017. pp. 3–14. 10.1145/3128572.3140444</mixed-citation></ref>
<ref id="pone.0243963.ref028"><label>28</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Hirano</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Takemoto</surname> <given-names>K</given-names></name>. <article-title>Simple iterative method for generating targeted universal adversarial perturbations</article-title>. <source>Algorithms</source>. <year>2020</year>;<volume>13</volume>: <fpage>268</fpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/a13110268" xlink:type="simple">10.3390/a13110268</ext-link></comment></mixed-citation></ref>
<ref id="pone.0243963.ref029"><label>29</label><mixed-citation publication-type="other" xlink:type="simple">Nicolae M-I, Sinn M, Tran MN, Buesser B, Rawat A, Wistuba M, et al. Adversarial Robustness Toolbox v1.0.0. 2018; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/1807.01069" xlink:type="simple">http://arxiv.org/abs/1807.01069</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref030"><label>30</label><mixed-citation publication-type="other" xlink:type="simple">Moosavi-Dezfooli S-M, Fawzi A, Frossard P. DeepFool: a simple and accurate method to fool deep neural networks. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE; 2016. pp. 2574–2582. 10.1109/CVPR.2016.282</mixed-citation></ref>
<ref id="pone.0243963.ref031"><label>31</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Rudin</surname> <given-names>C</given-names></name>. <article-title>Stop explaining black box machine learning models for high stakes decisions and use interpretable models instead</article-title>. <source>Nat Mach Intell</source>. <year>2019</year>;<volume>1</volume>: <fpage>206</fpage>–<lpage>215</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1038/s42256-019-0048-x" xlink:type="simple">10.1038/s42256-019-0048-x</ext-link></comment></mixed-citation></ref>
<ref id="pone.0243963.ref032"><label>32</label><mixed-citation publication-type="other" xlink:type="simple">Simonyan K, Zisserman A. Very deep convolutional networks for large-scale image recognition. 3rd International Conference on Learning Representations, ICLR 2015—Conference Track Proceedings. 2015.</mixed-citation></ref>
<ref id="pone.0243963.ref033"><label>33</label><mixed-citation publication-type="other" xlink:type="simple">He K, Zhang X, Ren S, Sun J. Deep Residual Learning for Image Recognition. 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE; 2016. pp. 770–778. 10.1109/CVPR.2016.90</mixed-citation></ref>
<ref id="pone.0243963.ref034"><label>34</label><mixed-citation publication-type="other" xlink:type="simple">Krizhevsky A. Learning Multiple Layers of Features from Tiny Images. Tech report, Univ Toronto. 2009; 10.1.1.222.9220</mixed-citation></ref>
<ref id="pone.0243963.ref035"><label>35</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Russakovsky</surname> <given-names>O</given-names></name>, <name name-style="western"><surname>Deng</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Su</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Krause</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Satheesh</surname> <given-names>S</given-names></name>, <name name-style="western"><surname>Ma</surname> <given-names>S</given-names></name>, <etal>et al</etal>. <article-title>ImageNet Large Scale Visual Recognition Challenge</article-title>. <source>Int J Comput Vis</source>. <year>2015</year>; <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s11263-015-0816-y" xlink:type="simple">10.1007/s11263-015-0816-y</ext-link></comment></mixed-citation></ref>
<ref id="pone.0243963.ref036"><label>36</label><mixed-citation publication-type="other" xlink:type="simple">Simon-Gabriel C-J, Ollivier Y, Bottou L, Schölkopf B, Lopez-Paz D. First-order adversarial vulnerability of neural networks and input dimension. Proceedings of the 36th International Conference on Machine Learning (ICML). PMLR; 2019. pp. 5809–5817. <ext-link ext-link-type="uri" xlink:href="http://proceedings.mlr.press/v97/simon-gabriel19a.html" xlink:type="simple">http://proceedings.mlr.press/v97/simon-gabriel19a.html</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref037"><label>37</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Chen</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Su</surname> <given-names>M</given-names></name>, <name name-style="western"><surname>Shen</surname> <given-names>S</given-names></name>, <name name-style="western"><surname>Xiong</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Zheng</surname> <given-names>H</given-names></name>. <article-title>POBA-GA: Perturbation optimized black-box adversarial attacks via genetic algorithm</article-title>. <source>Comput Secur</source>. <year>2019</year>;<volume>85</volume>: <fpage>89</fpage>–<lpage>106</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.cose.2019.04.014" xlink:type="simple">10.1016/j.cose.2019.04.014</ext-link></comment></mixed-citation></ref>
<ref id="pone.0243963.ref038"><label>38</label><mixed-citation publication-type="other" xlink:type="simple">Guo C, Gardner JR, You Y, Wilson AG, Weinberger KQ. Simple black-box adversarial attacks. Proc 36th Int Conf Mach Learn. 2019; 2484–2493. <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/1905.07121" xlink:type="simple">http://arxiv.org/abs/1905.07121</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref039"><label>39</label><mixed-citation publication-type="other" xlink:type="simple">Co KT, Muñoz-González L, de Maupeou S, Lupu EC. Procedural noise adversarial examples for black-box attacks on deep convolutional networks. Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security. New York, NY, USA: ACM; 2019. pp. 275–289. 10.1145/3319535.3345660</mixed-citation></ref>
<ref id="pone.0243963.ref040"><label>40</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Yu</surname> <given-names>T</given-names></name>, <name name-style="western"><surname>Hu</surname> <given-names>S</given-names></name>, <name name-style="western"><surname>Guo</surname> <given-names>C</given-names></name>, <name name-style="western"><surname>Chao</surname> <given-names>W-L</given-names></name>, <name name-style="western"><surname>Weinberger</surname> <given-names>KQ</given-names></name>. <article-title>A new defense against adversarial images: turning a weakness into a strength</article-title>. <source>Adv Neural Inf Process Syst</source>. <year>2019</year>; <fpage>1633</fpage>–<lpage>1644</lpage>.: 1910.07629</mixed-citation></ref>
<ref id="pone.0243963.ref041"><label>41</label><mixed-citation publication-type="other" xlink:type="simple">Xiao C, Zhong P, Zheng C. Enhancing adversarial defense by k-winners-take-all. Proc 8th Int Conf Learn Represent. 2020; <ext-link ext-link-type="uri" xlink:href="http://arxiv.org/abs/1905.10510" xlink:type="simple">http://arxiv.org/abs/1905.10510</ext-link></mixed-citation></ref>
<ref id="pone.0243963.ref042"><label>42</label><mixed-citation publication-type="journal" xlink:type="simple"><name name-style="western"><surname>Hwang</surname> <given-names>U</given-names></name>, <name name-style="western"><surname>Park</surname> <given-names>J</given-names></name>, <name name-style="western"><surname>Jang</surname> <given-names>H</given-names></name>, <name name-style="western"><surname>Yoon</surname> <given-names>S</given-names></name>, <name name-style="western"><surname>Cho</surname> <given-names>NI</given-names></name>. <article-title>PuVAE: a variational autoencoder to purify adversarial examples</article-title>. <source>IEEE Access</source>. <year>2019</year>;<volume>7</volume>: <fpage>126582</fpage>–<lpage>126593</lpage>. <comment>doi: <ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/ACCESS.2019.2939352" xlink:type="simple">10.1109/ACCESS.2019.2939352</ext-link></comment></mixed-citation></ref>
</ref-list>
</back>
</article>