Research Article

MedicalGuard: U-Net Model Robust against Adversarially Perturbed Images

Table 3

Architecture of the holdout model.

LevelConv layerFilterStrideOutput size

Input244, 244, 3

Contracting pathLevel 1Conv 13, 3, 641224, 244, 64
Conv 23, 3, 641224, 244, 64
Level 2Conv 33, 3, 1282112, 112, 128
Conv 43, 3, 1281112, 112, 128
Level 3Conv 53, 3, 256256, 56, 256
Conv 63, 3, 256156, 56, 256
Level 4Conv 73, 3, 512228, 28, 512
Conv 83, 3, 512128, 28, 512
Level 5Conv 93, 3, 1024214, 14, 1024
Conv 103, 3, 1024114, 14, 1024

BridgeLevel 6Conv 113, 3, 202827, 7, 1024
Conv 123, 3, 202817, 7, 2028

Expansive pathLevel 7Conv 133, 3, 1024114, 14, 1024
Conv 143, 3, 1024114, 14, 1024
Level 8Conv 153, 3, 512128, 28, 512
Conv 163, 3, 512128, 28, 512
Level 9Conv 173, 3, 256156, 56, 256
Conv 183, 3, 256156, 56, 256
Level 10Conv 193, 3, 1281112, 112, 128
Conv 203, 3, 1281112, 112, 128
Level 11Conv 213, 3, 641224, 244, 64
Conv 223, 3, 641224, 244, 64

OutputConv 231, 11224, 244, 1