Skip to content
Preprint

Text-Guided Diffusion-Based Adversarial Attacks on Chest X-Ray Images

Aug 2026 · 0 citations · 22 references
Computer Science

TL;DR

A text-guided diffusion-based adversarial framework that optimizes learnable text conditioning while keeping the diffusion generator and target classifier frozen, enabling adversarial generation through a learned image prior rather than direct pixel manipulation is proposed.

Abstract

As artificial intelligence is increasingly integrated into chest X-ray (CXR) interpretation, triage, and clinical decision support, understanding its vulnerability to adversarial manipulation is critical for safe deployment. Existing robustness evaluations, however, predominantly rely on pixel-space attacks that introduce numerically constrained perturbations but may not represent plausible radiographic variation. This limitation is particularly important in multi-disease CXR classification, where models simultaneously evaluate multiple overlapping pathologies and adversarial failures may alter several diagnostic predictions. We propose a text-guided diffusion-based adversarial framework that optimizes learnable text conditioning while keeping the diffusion generator and target classifier frozen, enabling adversarial generation through a learned image prior rather than direct pixel manipulation. We evaluate the framework across multiple classifier architectures in both binary atelectasis and multi-disease CXR classification and compare it with FGSM, PGD, and Carlini-Wagner attacks. Our approach consistently produced the greatest degradation in classifier performance, reducing AUROC to 0.3885-0.5646 in binary classification and 0.4441-0.4878 in the multi-disease setting, while achieving superior image fidelity (SSIM 0.9080, LPIPS 0.1670, FID 51.23). Importantly, clinician interpretation remained unchanged for 95.9% of binary and 73.8% of multi-disease adversarial images despite substantial changes in model predictions. These findings reveal a clinically important discrepancy between human and machine interpretation and demonstrate the need to extend medical AI robustness evaluation beyond conventional pixel-space attacks toward generative threat models that can expose failures under visually and clinically plausible image variations.

View source

Similar papers

Conference Aug 2026

A Leakage-Aware Deep Learning Framework for Reliable Chest X-ray Classification with Anatomically Constrained Explanations

While Chest X-ray (CXR) classification effectively aids respiratory disease assessment, existing models often suffer from data leakage—the presence of duplicate or near-duplicate images across training, validation, and test sets that can artificially inflate performance metrics—and poor interpretability by highlighting...

Ly Yen Nguyen-Thi, L. T. Tran, Thien B. Nguyen-Tat · 0 citations
Aug 2026

Anatomical Prior-Guided Black-Box Attack Optimization for Prostate Tumor mpMRI Classification Models.

Prostate cancer is a highly prevalent malignancy, and deep learning has significantly advanced di agnostic models based on multi-parametric MRI (mpMRI). However, the robustness of these models is threatened by adversarial attacks, potentially leading to fatal misdiagnoses and impeding clinical translation. Unlike natur...

Yu Zhang, Jun-Qiang Qiu, Dong-Hui Li et al. · 0 citations
Sep 2026

Seeing Through Threats: Adversarial Detection Through Explainability (ADEx)

Deep Neural Networks (DNNs) remain vulnerable to adversarial perturbations, raising significant concerns in image processing applications, particularly in high-stakes domains such as medical imaging and security-critical systems. Most existing defense strategies are limited by domain specificity, architectural dependen...

Syamantak Sarkar, Nirmal Joseph, Sudhish N. George et al. · 0 citations
Conference Aug 2026

Benchmarking Test-Time Adaptation for Multi-Label Chest X-ray Classification under Distribution Shift

Although AI models achieve impressive performance on chest X-ray benchmarks, their deployment in real-world clinical settings remains challenging due to performance degradation under unpredictable conditions. To understand how these AI models can adapt in practice, we systematically evaluate several Test-Time Adaptatio...

Duc-Ngo Van, Kim-Hung Le · 0 citations
#explainable ai Review Open access Sep 2026

Artificial Intelligence in Medical Imaging: A Review of Radiodiagnosis in Indian Perspectives

It is concluded that AI literacy is no longer optional: the radiologist's role is not threatened by AI but transformed by it—from film reader to AI-augmented clinical imaging physician capable of extending world-class diagnostic care to underserved populations across India and globally.

Emily Das, Rasel Mondal, Ashim Dhor et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.