Adversarial Attacks on Medical Hyperspectral Imaging Exploiting Spectral-Spatial Dependencies and Multiscale Features
Pith reviewed 2026-05-16 15:06 UTC · model grok-4.3
The pith
Adversarial attacks on medical hyperspectral images gain effectiveness by modeling spectral-spatial dependencies and multiscale features.
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The paper claims that existing adversarial attack methods fail to leverage the unique spectral-spatial properties of medical hyperspectral images, including local tissue relationships and multiscale structures. By developing a method that explicitly models these dependencies, it generates perturbations that more effectively reduce the performance of lesion classification in tumor areas on brain and choledoch datasets, all while keeping the magnitude of changes low. This reveals weaknesses in current models and supplies stronger examples for defense development.
What carries the argument
Structured adversarial attack framework modeling neighborhood dependencies and hierarchical spectral-spatial features to produce anatomically consistent perturbations.
If this is right
- Attacks degrade lesion-related classification performance more effectively in critical tumor regions than baselines.
- Perturbations maintain low magnitude while achieving stronger attack results.
- Generated samples improve adversarial training for building more robust MHSI models.
- Results highlight clinically relevant robustness weaknesses in current MHSI classification systems.
Where Pith is reading between the lines
- The modeling approach could extend to other spectral imaging tasks where tissue or material relationships matter.
- Models trained with these stronger examples might require fewer retraining cycles to reach reliable performance.
- Similar dependency modeling might help design inherently robust networks that reduce reliance on post-hoc defenses.
Load-bearing premise
Existing attack methods do not sufficiently exploit MHSI-specific properties such as local tissue relationships and multiscale spectral-spatial structures, so modeling these will produce more effective and anatomically consistent perturbations.
What would settle it
Running the proposed attack alongside baselines on the brain and choledoch datasets and finding no greater drop in lesion classification accuracy or requiring higher perturbation magnitudes than the baselines.
Figures
read the original abstract
Medical hyperspectral imaging (MHSI) has shown strong potential for disease diagnosis by capturing spectral-spatial information of tissues. While deep learning has substantially improved MHSI classification accuracy, its robustness remains limited due to the well-known trade-off between accuracy and robustness in Deep Neural Networks (DNNs). This issue is particularly critical in MHSI, where reliable prediction depends on local tissue relationships and multiscale spectral-spatial structures. A practical way to improve robustness is to identify the most unstable adversarial examples and incorporate them into adversarial training. However, existing attack methods do not sufficiently exploit these MHSI-specific properties, leading to suboptimal attack effectiveness and limited value for robustness enhancement. To address this gap, we propose a structured adversarial attack framework for MHSI that progressively models its local spectral-spatial dependencies and multiscale hierarchical representations. The proposed method generates anatomically consistent perturbations by modeling neighborhood dependencies and hierarchical spectral-spatial features. Experiments on the brain and choledoch datasets show that our method more effectively degrades lesion-related classification performance in critical tumor regions than existing baselines while maintaining low perturbation magnitude. These results reveal a clinically relevant robustness weakness in current MHSI models and provide stronger adversarial samples for developing targeted defense strategies.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript proposes a structured adversarial attack framework for medical hyperspectral imaging (MHSI) that progressively models local spectral-spatial dependencies and multiscale hierarchical representations to generate anatomically consistent perturbations. Experiments on brain and choledoch datasets are claimed to show that the method degrades lesion-related classification performance more effectively in critical tumor regions than existing baselines while maintaining low perturbation magnitude.
Significance. If the central experimental claims hold after providing missing details, the work would be significant for exposing robustness gaps in MHSI DNN classifiers and supplying stronger adversarial examples for targeted defense strategies in medical imaging. It directly targets MHSI-specific properties (neighborhood tissue relationships and multiscale spectral-spatial structure) that prior attacks overlook.
major comments (2)
- [Abstract and Experiments] Abstract and Experiments: The load-bearing claim that the method 'more effectively degrades lesion-related classification performance in critical tumor regions' lacks any definition of those regions via an independent, reproducible criterion (e.g., expert-annotated masks or fixed saliency threshold independent of the attack). No per-region metrics (accuracy, AUC, or F1 inside the masks) or masked perturbation-norm comparisons (L2 or spectral L-infinity) versus baselines are reported, so the region-specific advantage cannot be verified and may be an evaluation artifact.
- [Method] Method: No equations, loss formulation, or implementation details are supplied for how neighborhood dependencies are modeled, how the hierarchical spectral-spatial features are extracted, or how the progressive attack is constructed. Without these, it is impossible to assess whether the framework genuinely exploits MHSI structure or to reproduce the reported superiority.
minor comments (1)
- [Abstract] The abstract states that existing attacks 'do not sufficiently exploit' MHSI properties but provides no quantitative comparison (e.g., attack success rate or perturbation size) that isolates the contribution of the proposed spectral-spatial modeling.
Simulated Author's Rebuttal
We thank the referee for the constructive and detailed feedback, which helps clarify key aspects of our work. We address each major comment below and have revised the manuscript to improve verifiability and reproducibility.
read point-by-point responses
-
Referee: [Abstract and Experiments] Abstract and Experiments: The load-bearing claim that the method 'more effectively degrades lesion-related classification performance in critical tumor regions' lacks any definition of those regions via an independent, reproducible criterion (e.g., expert-annotated masks or fixed saliency threshold independent of the attack). No per-region metrics (accuracy, AUC, or F1 inside the masks) or masked perturbation-norm comparisons (L2 or spectral L-infinity) versus baselines are reported, so the region-specific advantage cannot be verified and may be an evaluation artifact.
Authors: We agree that the original presentation did not sufficiently define the tumor regions or provide the requested per-region metrics, which limits independent verification. In the revised manuscript, we explicitly define critical tumor regions using the expert-annotated masks available in both the brain and choledoch datasets. We now report accuracy, AUC, and F1 scores computed exclusively inside these masks, along with masked L2 and spectral L-infinity perturbation norms for our method versus all baselines. These additions confirm the claimed region-specific degradation while preserving low overall perturbation magnitude. revision: yes
-
Referee: [Method] Method: No equations, loss formulation, or implementation details are supplied for how neighborhood dependencies are modeled, how the hierarchical spectral-spatial features are extracted, or how the progressive attack is constructed. Without these, it is impossible to assess whether the framework genuinely exploits MHSI structure or to reproduce the reported superiority.
Authors: We acknowledge that the initial submission omitted the explicit equations and algorithmic details needed for full reproducibility. The revised manuscript now includes the complete loss formulation for modeling local spectral-spatial neighborhood dependencies, the mathematical definition of the multiscale hierarchical feature extraction process, and the step-by-step construction of the progressive attack. We have added the full objective function, pseudocode for the attack algorithm, and all relevant implementation hyperparameters to allow readers to assess how MHSI-specific properties are exploited and to reproduce the results. revision: yes
Circularity Check
No significant circularity; claims rest on proposed method and experiments
full rationale
The paper introduces a new structured adversarial attack framework for MHSI that models neighborhood dependencies and hierarchical spectral-spatial features. The central claim of superior degradation in critical tumor regions is supported by reported experiments on brain and choledoch datasets rather than by any self-referential definition, fitted parameter renamed as prediction, or load-bearing self-citation chain. No equations or derivation steps in the provided text reduce the output to the input by construction. Minor self-citation risk is possible in a full manuscript but is not load-bearing here.
Axiom & Free-Parameter Ledger
Reference graph
Works this paper leans on
-
[1]
Medical hyperspectral imaging: a review,
Guolan Lu and Baowei Fei, “Medical hyperspectral imaging: a review,” Journal of biomedical optics, vol. 19, no. 1, pp. 010901–010901, 2014
work page 2014
-
[2]
Spectral-spatial classification for noninvasive cancer detection using hyperspectral imaging,
Guolan Lu, Luma Halig, Dongsheng Wang, Xulei Qin, Zhuo Georgia Chen, and Baowei Fei, “Spectral-spatial classification for noninvasive cancer detection using hyperspectral imaging,”Journal of biomedical optics, vol. 19, no. 10, pp. 106004–106004, 2014
work page 2014
-
[3]
Deep learning in medical hyperspectral images: A review,
Rong Cui, He Yu, Tingfa Xu, Xiaoxue Xing, Xiaorui Cao, Kang Yan, and Jiexi Chen, “Deep learning in medical hyperspectral images: A review,”Sensors, vol. 22, no. 24, pp. 9790, 2022
work page 2022
-
[4]
Daya Kumar, Abhijith Sharma, and Apurva Narayan, “Attacking cnns in histopathology with snap: sporadic and naturalistic adversarial patches (student abstract),” inProceedings of the AAAI Conference on Artificial Intelligence, 2024, vol. 38, pp. 23550–23551
work page 2024
-
[5]
Explaining and Harnessing Adversarial Examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy, “Explaining and harnessing adversarial examples,”arXiv preprint arXiv:1412.6572, 2014
work page internal anchor Pith review Pith/arXiv arXiv 2014
-
[6]
˙Inci M Baytas ¸, “Predicting progression from mild cognitive impairment to alzheimer’s dementia with adversarial attacks,”IEEE Journal of Biomedical and Health Informatics, 2024
work page 2024
-
[7]
Microscopic hyperspectral image classification based on fusion transformer with parallel cnn,
Weijia Zeng, Wei Li, Mengmeng Zhang, Hao Wang, Meng Lv, Yue Yang, and Ran Tao, “Microscopic hyperspectral image classification based on fusion transformer with parallel cnn,”IEEE Journal of Biomedical and Health Informatics, vol. 27, no. 6, pp. 2910–2921, 2023
work page 2023
-
[8]
Modern trends in hyperspectral image analysis: A review,
Muhammad Jaleed Khan, Hamid Saeed Khan, Adeel Yousaf, Khurram Khurshid, and Asad Abbas, “Modern trends in hyperspectral image analysis: A review,”Ieee Access, vol. 6, pp. 14118–14129, 2018
work page 2018
-
[9]
Trends in deep learning for medical hyperspectral image analysis,
Uzair Khan, Sidike Paheding, Colin P Elkin, and Vijaya Kumar Dev- abhaktuni, “Trends in deep learning for medical hyperspectral image analysis,”IEEE Access, vol. 9, pp. 79534–79548, 2021
work page 2021
-
[10]
Explor- ing hyperspectral histopathology image segmentation from a deformable perspective,
Xingran Xie, Ting Jin, Boxiang Yun, Qingli Li, and Yan Wang, “Explor- ing hyperspectral histopathology image segmentation from a deformable perspective,” inProceedings of the 31st ACM International Conference on Multimedia, 2023, pp. 242–251
work page 2023
-
[11]
Hyperspectral imaging in medical applications,
Baowei Fei, “Hyperspectral imaging in medical applications,” inData handling in science and technology, vol. 32, pp. 523–565. Elsevier, 2019
work page 2019
-
[12]
Danyang Peng, Haoran Feng, Jun Wu, Yi Wen, Tingting Han, Yuanyuan Li, Guangyu Yang, and Lei Qu, “Robust hyperspectral image classifi- cation using a multi-scale transformer with long-short-distance spatial- spectral cross-attention,”IEEE Transactions on Geoscience and Remote Sensing, 2024
work page 2024
-
[13]
Medical hy- perspectral image classification based on end-to-end fusion deep neural network,
Xueling Wei, Wei Li, Mengmeng Zhang, and Qingli Li, “Medical hy- perspectral image classification based on end-to-end fusion deep neural network,”IEEE Transactions on Instrumentation and Measurement, vol. 68, no. 11, pp. 4481–4492, 2019
work page 2019
-
[14]
Multifeature collaborative adversarial attack in multimodal remote sensing image classification,
Cheng Shi, Yenan Dang, Li Fang, Minghua Zhao, Zhiyong Lv, Qiguang Miao, and Chi-Man Pun, “Multifeature collaborative adversarial attack in multimodal remote sensing image classification,”IEEE Transactions on Geoscience and Remote Sensing, vol. 60, pp. 1–15, 2022
work page 2022
-
[15]
Deep learning for hyperspectral image classification: An overview,
Shutao Li, Weiwei Song, Leyuan Fang, Yushi Chen, Pedram Ghamisi, and Jon Atli Benediktsson, “Deep learning for hyperspectral image classification: An overview,”IEEE Transactions on Geoscience and Remote Sensing, vol. 57, no. 9, pp. 6690–6709, 2019
work page 2019
-
[16]
Feature extraction for hyperspectral image classification: A review,
Brajesh Kumar, Onkar Dikshit, Ashwani Gupta, and Manoj Kumar Singh, “Feature extraction for hyperspectral image classification: A review,”International Journal of Remote Sensing, vol. 41, no. 16, pp. 6248–6287, 2020
work page 2020
-
[17]
Hybridsn: Exploring 3-d–2-d cnn feature hierarchy for hyperspectral image classification,
Swalpa Kumar Roy, Gopal Krishna, Shiv Ram Dubey, and Bidyut B Chaudhuri, “Hybridsn: Exploring 3-d–2-d cnn feature hierarchy for hyperspectral image classification,”IEEE Geoscience and Remote Sensing Letters, vol. 17, no. 2, pp. 277–281, 2019
work page 2019
-
[18]
Zilong Zhong, Jonathan Li, Zhiming Luo, and Michael Chapman, “Spectral–spatial residual network for hyperspectral image classification: A 3-d deep learning framework,”IEEE Transactions on Geoscience and Remote Sensing, vol. 56, no. 2, pp. 847–858, 2017
work page 2017
-
[19]
Yonghao Xu, Bo Du, and Liangpei Zhang, “Self-attention context network: Addressing the threat of adversarial attacks for hyperspectral image classification,”IEEE Transactions on Image Processing, vol. 30, pp. 8671–8685, 2021
work page 2021
-
[20]
Blood cell classification based on hyperspectral imaging with modulated gabor and cnn,
Qian Huang, Wei Li, Baochang Zhang, Qingli Li, Ran Tao, and Nigel H Lovell, “Blood cell classification based on hyperspectral imaging with modulated gabor and cnn,”IEEE journal of biomedical and health informatics, vol. 24, no. 1, pp. 160–170, 2019
work page 2019
-
[21]
Factor space and spectrum for medical hyperspectral image seg- mentation,
Boxiang Yun, Qingli Li, Lubov Mitrofanova, Chunhua Zhou, and Yan Wang, “Factor space and spectrum for medical hyperspectral image seg- mentation,” inInternational Conference on Medical Image Computing and Computer-Assisted Intervention. Springer, 2023, pp. 152–162
work page 2023
-
[22]
Universal object-level adversarial attack in hyperspectral image classification,
Cheng Shi, Mengxin Zhang, Zhiyong Lv, Qiguang Miao, and Chi-Man Pun, “Universal object-level adversarial attack in hyperspectral image classification,”IEEE Transactions on Geoscience and Remote Sensing, vol. 61, pp. 1–14, 2023
work page 2023
-
[23]
Sparse adversarial attack method for deep learning hyperspectral image classi- fication models,
Zhaoxia Yin, Lichun Tang, Cong Kong, Hang Su, and Bin Luo, “Sparse adversarial attack method for deep learning hyperspectral image classi- fication models,” CN Patent: CN117079137B, 2025, Granted patent
work page 2025
-
[24]
Bing Tu, Wangquan He, Qianming Li, Yishu Peng, and Antonio Plaza, “A new context-aware framework for defending against adversarial attacks in hyperspectral image classification,”IEEE Transactions on Geoscience and Remote Sensing, vol. 61, pp. 1–14, 2023
work page 2023
-
[25]
Lichun Tang, Zhaoxia Yin, Hang Su, Wanli Lyu, and Bin Luo, “Wfss: weighted fusion of spectral transformer and spatial self-attention for robust hyperspectral image classification against adversarial attacks,” Visual Intelligence, vol. 2, no. 1, pp. 5, 2024
work page 2024
-
[26]
Attack-invariant attention feature for adversarial defense in hyperspectral image classification,
Cheng Shi, Ying Liu, Minghua Zhao, Chi-Man Pun, and Qiguang Miao, “Attack-invariant attention feature for adversarial defense in hyperspectral image classification,”Pattern Recognition, vol. 145, pp. 109955, 2024
work page 2024
-
[27]
Yichu Xu, Yonghao Xu, Hongzan Jiao, Zhi Gao, and Lefei Zhang, “S3anet: Spatial–spectral self-attention learning network for defending against adversarial attacks in hyperspectral image classification,”IEEE Transactions on Geoscience and Remote Sensing, vol. 62, pp. 1–13, 2024
work page 2024
-
[28]
In-vivo hyperspectral human brain image database for brain cancer detection,
Himar Fabelo, Samuel Ortega, Adam Szolna, Diederik Bulters, Juan F Pi˜neiro, Silvester Kabwama, Aruma JO’Shanahan, Harry Bulstrode, Sara Bisshopp, B Ravi Kiran, et al., “In-vivo hyperspectral human brain image database for brain cancer detection,”IEEE Access, vol. 7, pp. 39098–39116, 2019
work page 2019
-
[29]
A multidimensional choledoch database and benchmarks for cholangiocarcinoma diagnosis,
Qing Zhang, Qingli Li, Guanzhen Yu, Li Sun, Mei Zhou, and Junhao Chu, “A multidimensional choledoch database and benchmarks for cholangiocarcinoma diagnosis,”IEEE access, vol. 7, pp. 149414– 149421, 2019
work page 2019
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.