Research Article

MedicalGuard: U-Net Model Robust against Adversarially Perturbed Images

Table 5

Comparison between original label and output result of the model with no defense, the baseline model, and the proposed model. The model with no defense is a U-Net model with no defense against adversarial examples. The baseline model is a U-Net model to which the existing adversarial training method has been applied.

DescriptionCase 1Case 2Case 3

Adversarial example

Original label

No defense
Baseline
Proposed