Medical image diagnosis method based on Lipschitz constraint
Through Lipschitz constraints and sparse projection weight matrix update, the robustness and computing efficiency of the intelligent medical imaging diagnosis system are improved, and the problems of insufficient robustness and high resource consumption in the existing technology are solved. It is suitable for medical imaging diagnosis systems.
Patent Information
- Application Number
- CN202510304859.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-14
- Publication Date
- 2025-07-01
AI Technical Summary
When facing confrontational attacks, existing intelligent medical imaging diagnosis systems are not robust enough and have high computing resource consumption, making it difficult to effectively apply on resource-constrained devices.
The medical imaging diagnosis method based on Lipschitz constraint is adopted, and the model weight is updated by calculating the loss function value and the Lipschitz constant constraint, combining the sparse weight matrix and the projection weight matrix to reduce the model's sensitivity to perturbation, improve robustness and reduce computing resource consumption.
While improving the robustness of the model, it reduces computing resource consumption, ensures the stability and response speed of the model when facing adversarial attacks, and is suitable for resource-constrained medical devices.
Smart Images

Figure CN120236131A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the fields of artificial intelligence and medical imaging, and relates to a medical imaging diagnosis method based on Lipschitz constraint. Background Art
[0002] Intelligent medical imaging diagnosis systems have made significant progress in the field of medical image analysis in recent years. By using artificial intelligence technologies such as deep learning (e.g., convolutional neural network, CNN), the diagnostic efficiency and accuracy have been greatly improved. However, with the wide application of these technologies, especially when it comes to issues related to security and robustness, there are still many challenges in the existing technologies.
[0003] In recent years, adversarial attacks on deep learning models, especially medical imaging models, have become an important research direction. Adversarial attacks can cause the model to produce incorrect diagnostic results by adding tiny perturbations to the input image. Some existing defense methods mainly focus on adversarial sample training and the processing of input images, but these methods often lack theoretical basis and the defense effect is unstable in practical applications.
[0004] For example, Goodfellow et al. proposed the concept of adversarial samples in their paper "Explaining and Harnessing Adversarial Examples" and explored the impact of adversarial attacks on deep neural networks. To address this challenge, researchers have proposed defense strategies including adversarial training, gradient masking, etc., but most of these methods rely on a large amount of computing resources and perform poorly in the face of more complex attacks.
[0005] Related patents such as CN119339257A and CN114091568A propose methods based on adversarial training and defense models, but these methods still have some defects. First, the defense mechanism often increases the computational complexity of the model, making it difficult to apply on resource-constrained devices; second, most of these methods are based on empirical designs and lack theoretical support, and cannot effectively cope with various new types of adversarial attacks.
[0006] Currently, many defense methods for enhancing robustness, such as training driven by integrated adversarial attacks, usually rely on the combination and training of multiple adversarial attack algorithms. Although this method can effectively improve the robustness of the model and enable it to defend against multiple attacks (as described in CN118734931A), it also brings a high consumption of computing resources. Specifically, training by integrating multiple adversarial attack algorithms requires independent calculation and training for each attack, and when fusing the algorithms, a large number of similarity calculations and iterative optimizations must be carried out, which will significantly increase the calculation time and hardware requirements.
[0007] In addition, the integration method requires the training and adjustment of multiple models, further increasing the complexity and computational overhead of the model. For application scenarios with high real-time requirements such as intelligent medical image diagnosis, this high computational consumption may affect the response speed and actual application effect of the model.
[0008] Therefore, how to improve the robustness of the model and reduce the consumption of computing resources while improving the robustness of the model is an urgent problem to be solved in the current technology. Summary of the Invention
[0009] To solve the above-mentioned problems of the prior art, the present invention adopts a medical image diagnosis method based on Lipschitz constraint, including: obtaining medical image data, inputting the medical image data into a trained medical image diagnosis model to obtain a diagnosis result;
[0010] The training process of the medical image diagnosis model includes:
[0011] S1. Obtain a medical image data set, which includes clean samples and adversarial samples;
[0012] S2. Input the samples in the medical image data set into the medical image diagnosis model to obtain the prediction probability of the samples for each category; the category with the largest prediction probability is the diagnosis result;
[0013] S3. Calculate the loss function value according to the prediction probability of the samples for each category and the Lipschitz constraint; construct a certification condition, and update the medical image diagnosis model based on the certification condition according to the loss function value. When the loss function value is the smallest, the trained medical image diagnosis model is obtained.
[0014] Calculating the loss function value includes: respectively calculating the comprehensive prediction probabilities f(x) max 、f(x) second of the maximum prediction category and the second-largest prediction category according to the prediction probability of the samples for each category, and according to the comprehensive prediction probabilities f(x) max 、f(x) secondCalculate the cross - entropy loss functions of the maximum predicted class, the second - largest predicted class and the true class of the sample respectively, and perform weighted combination on the cross - entropy loss functions of the maximum predicted class and the second - largest predicted class to obtain the final loss function value.
[0015] Calculate the comprehensive prediction probability f(x) of the maximum predicted class max including: calculating the weight vector W corresponding to the maximum predicted class in the last network layer of the medical image diagnosis model m t ax and the weight vector W corresponding to the true class of the sample y t of the inter - class similarity measure head_ji max , according to the weight vector W corresponding to the true class of the sample y t calculate the local Lipschitz constant and obtain the upper bound ε of the perturbation strength max , according to the prediction probability f′(x) of the maximum predicted class max , the inter - class similarity measure head_ji max , the local Lipschitz constant and the upper bound ε of the perturbation strength max calculate the comprehensive prediction probability f(x) of the maximum predicted class max .
[0016] The certification condition is L ≤ Δ / ε max ; where L is the local Lipschitz constant, Δ is the minimum confidence interval, and ε max is the upper bound of the perturbation strength.
[0017] Updating the medical image diagnosis model includes: calculating the Lipschitz constant of the medical image diagnosis model at the current iteration t. If the Lipschitz constant is greater than Δ / ε max , then calculate the sparse weight matrix and the projection weight matrix weighted combination of the sparse weight matrix and the projection weight matrix to obtain the updated weight matrix W of the medical image diagnosis model t+1 ; otherwise, do not update.
[0018] Calculating the sparse weight matrix includes:
[0019]
[0020] where W t is the weight matrix of the entire medical image diagnosis model at the current iteration t, ({w∈|W t||w≠0},γ)>0) represents the weight matrix composed of weight elements w in matrix |W t | that are not equal to 0 and greater than γ, where γ is the sparsity control parameter, and |W t | represents taking the absolute value of all elements in the weight matrix W t and sign(·) is the sign function.
[0021] Calculating the projection weight matrix includes:
[0022]
[0023] Among them, is the weight gradient, and L MDB (W t ) is the loss function value, is the initial value of the projection weight matrix, χ is the residual term, representing the gap between the current weight matrix and the authentication condition, π is the alignment metric between the projection direction and the gradient, v is the adaptive step size scaling factor, μ is the regularization coefficient, and cW t is the authentication condition constraint direction vector.
[0024] The calculation process of the residual term X includes:
[0025] Constructing an optimization problem:
[0026]
[0027] Solving the optimization problem to obtain the authentication weight matrix Calculating the projection weight matrix and the norm of the difference between the authentication weight matrix to obtain the residual term X; among them, is the weight vector corresponding to the true category of the sample in the last network layer of the medical image diagnosis model, F(t′) is the general term formula of the Fibonacci sequence, and t′ is the index of the iteration number.
[0028] Calculating the alignment metric π between the projection direction and the gradient includes: calculating the authentication weight matrix W c t ertified and the difference between the projection weight matrix Calculating the weight gradient dW t and the difference to obtain the alignment metric π between the projection direction and the gradient.
[0029] Calculating the authentication constraint direction vector cW t includes:
[0030] Beneficial effects:
[0031] 1. The present invention uses the Lipschitz constant regularization technique to add a penalty term L of the Lipschitz constant to the loss function, further constraining the gradient change of the model, making the model more robust in the face of adversarial perturbations; 2. The present invention combines the concept of the robustness boundary to constrain the Lipschitz constant L according to the minimum confidence interval and the upper bound of the perturbation strength, thereby constraining the perturbation range of the training data, ensuring that the model can operate stably within this boundary, and improving the model's resistance to adversarial samples; 3. The present invention calculates the sparse weight matrix and the projection weight matrix The sparse weight matrix retains the features that meet the threshold condition, that is, the features related to the disease, filters out irrelevant noise, reduces the sensitivity of the model to minor perturbations, reduces the computational amount, and meets the requirements of medical certification defense; The projection weight matrix dynamically selects the projection strategy according to the residual term of the current iteration, the alignment metric between the projection direction and the gradient, and the adaptive step size scaling factor, ensuring the achievement of the optimal defense effect and improving the model robustness; Combining the sparse weight matrix and the projection weight matrix can improve the model robustness while reducing the waste of computing resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 is a structural diagram of a medical image diagnosis method based on Lipschitz constraint provided by an embodiment of the present invention;
[0033] Figure 2 is a decision-making schematic diagram of the medical image diagnosis model provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0034] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0035] As Figure 1 shown, the present invention adopts a medical image diagnosis method based on Lipschitz constraint, including: obtaining medical image data, inputting the medical image data into a trained medical image diagnosis model, and obtaining a diagnosis result;
[0036] The training process of the medical image diagnosis model includes:
[0037] S1. Obtain a medical image dataset, which includes a clean dataset and an adversarial dataset; the clean dataset includes clean medical image data samples, and the adversarial dataset includes adversarial medical image data samples, i.e., perturbed medical image data.
[0038] Medical image data (such as CT, MRI) is a high-dimensional tensor, and the perturbation usually comes from noise, equipment differences, or minor anatomical variations.
[0039] S2. Input the samples in the medical image dataset into the medical image diagnosis model to obtain the prediction probabilities of the samples for each category; the category with the highest prediction probability is the diagnosis result.
[0040] The medical image diagnosis model is an ordinary convolutional network. When dealing with a small dataset, it includes four convolutional layers and two fully connected layers. When dealing with a large dataset, it includes eight convolutional layers and two fully connected layers. For even larger datasets, additional convolutional layers can be stacked.
[0041] The weights of the entire medical image diagnosis model are \(W\). t , and the weight matrix of the last fully connected layer of the medical image diagnosis model is The weight matrix representing the non-diseased class, The weight matrix representing the diseased class.
[0042] As Figure 2 shown, the two black dashed circles on the left correspond to the magnitude of the adversarial attack perturbation, and the black circle on the right corresponds to the range of the Lipschitz constraint; in the medical image diagnosis model (i.e., the classification network), the different-shaped circles and triangles correspond to the samples of the clean dataset and the adversarial dataset respectively; different colors of the same shape correspond to different samples of the same dataset. The ranges encompassed around the circles and triangles in the decision space correspond to the fluctuation ranges of different datasets mapped by the classification network.
[0043] This figure represents different data samples (clean samples and adversarial samples) passing through the medical image diagnosis model. The medical image diagnosis model learns and extracts the features of the sample data, thus mapping them into the decision space.
[0044] The prediction probability \(f(x)\) of the sample for each category is in the range \([0, 1]\). The categories include diseased and non-diseased, and the labels for diseased and non-diseased are 1 and 0 respectively, and the decision threshold is 0.5.
[0045] S3. Calculate the loss function value based on the prediction probabilities of the sample for each category and the Lipschitz constraint; construct the certification condition, and update the medical image diagnosis model based on the certification condition according to the loss function value. When the loss function value is minimized, the trained medical image diagnosis model is obtained.
[0046] Specifically, constructing the certification condition includes:
[0047] The bounded perturbation δ is defined as an l2-bounded perturbation, i.e., ||δ||2 ≤ ε max , simulating common noises or imaging errors, where ε max is the upper bound of the perturbation intensity.
[0048] For the diseased sample x, it is necessary to ensure that it can still be correctly classified after perturbation:
[0049]
[0050] Then it is necessary to determine the minimum confidence interval Δ of the model for the diseased sample, i.e.:
[0051] f(x) ≥ 0.5 + Δ
[0052] Then the output change after perturbation needs to satisfy:
[0053] f(x + d) ≥ f(x) - L × ε max ≥ 0.5
[0054] Then for any perturbation δ, there is:
[0055] ∣f(x + d) - f(x)∣ ≤ L||δ||2 ≤ L·ε max
[0056] To ensure f(x + δ) ≥ 0.5, it is necessary to satisfy:
[0057] f(x) - L × ε max ≥ 0.5 → Δ ≥ L × ε max
[0058] Therefore, the certification radius is:
[0059]
[0060] Then the Lipschitz constant L of the model satisfies L ≤ Δ / ε max and ε certified ≥ ε max ; ε certified ≥ ε max indicates that the model is absolutely reliable within the noise range allowed in medicine.
[0061] The minimum confidence interval Δ needs to be set according to the clinical risk, and the upper bound ε of the perturbation intensity max refers to the noise level of medical imaging equipment. In one embodiment, if the cost of missed diagnosis is extremely high, it can be required that Δ ≥ 0.3; the l2-noise standard deviation of MRI is about 0.1, then ε is set max ≤ 0.2.
[0062] The loss function L MDB is:
[0063] L MDB =(1 - λ)·CE(f(x) second , y)+λ·CE(f(x) max , y)
[0064] f(x) max =f′(x) max +L·ε max ·head_ji max
[0065] f(x) second =f′(x) second +L·ε max ·head_ji second
[0066] Among them, λ is a balance factor that controls the weights of the two cross - entropy losses, with a range of [0, 1]. It is used to adjust the model's confidence in the largest category and the misleading attention to the second - largest category. The initial value is set to 0.5, indicating equal attention, and it is adjusted according to the robustness under adversarial attacks on the validation set: if the model is easily misled by adversarial samples (the second - largest category is activated), increase λ; if the classification confidence is insufficient, decrease λ.
[0067] CE is the cross - entropy loss function. If the second - largest predicted category of the model is the positive class (i.e., diseased), then CE(f(x) second , y)= - [ylogf(x) second +(1 - y)log(1 - f(x) second )]; otherwise, CE(f(x) second , y)= - [(1 - y)logf(x) second +ylog(1 - f(x) second )]. If the largest predicted category of the model is the positive class (i.e., diseased), then CE(f(x) max , y)= - [ylogf(x) max +(1 - y)log(1 - f(x) max )]; otherwise CE(f(x) max , y)= - [(1 - y)logf(x) max +ylog(1 - f(x) max )]. y is the true category of the sample, and f(x) max , f(x) second are the comprehensive prediction probabilities of the largest predicted category and the second - largest predicted category predicted by the model respectively; f′(x) max , f′(x) secondThey are the prediction probabilities of the maximum prediction category and the second - largest prediction category predicted by the model respectively; the maximum prediction category predicted by the model is the category with the largest prediction probability, and the second - largest prediction category predicted by the model is the category with the second - largest prediction probability;
[0068] is the local Lipschitz constant of the last fully - connected layer of the medical image diagnosis model with respect to the true category y, which reflects the sensitivity of the category weight vector, W y t is the weight vector of category y in the last fully - connected layer of the medical image diagnosis model. The smaller the L value, the stronger the robustness of the decision boundary of the true category y to input perturbations;
[0069] ε max is the upper bound of the perturbation intensity, that is, the maximum allowable perturbation range of the medical image, which is consistent with ε in the certification condition max and is determined by clinical experts. For example, the allowable noise level, deformation amplitude, etc. in CT / MRI images.
[0070] head_ji max and head_ji second is the similarity measure between categories, that is, the similarity between the weight vectors corresponding to the maximum prediction category and the second - largest prediction category in the last fully - connected layer of the medical image diagnosis model and the weight vector corresponding to the true category, which is used to quantify the degree of confusion between categories. The calculation method is:
[0071]
[0072] are the weight vectors corresponding to the maximum prediction category and the second - largest prediction category in the last fully - connected layer of the medical image diagnosis model respectively. cos_similarity is the cosine similarity, and the range of the cosine similarity is [- 1,1]. The larger the value, the closer the category weight directions are, and the more likely the model is to be confused.
[0073] Updating the medical image diagnosis model according to the loss function value includes:
[0074] Calculating the Lipschitz constant of the medical image diagnosis model at the current iteration t. If the Lipschitz constant is greater than - Δ / ε max , then calculate the sparse weight matrix and the projection weight matrix According to the sparse weight matrix and the projection weight matrix Calculate the updated weight matrix of the medical image diagnosis model Otherwise, it indicates that the current weight matrix already satisfies the Lipschitz constraint and does not require further optimization. Do not update it and directly proceed to the next iteration; where α is the weight factor.
[0075] Calculate the sparse weight matrix Including:
[0076]
[0077] Among them, W t is the weight matrix of the entire medical image diagnosis model at the current iteration t; ({w ∈ |W t ||w ≠ 0}, γ) > 0) represents the weight matrix composed of weight elements w in the matrix |W t | that are not equal to 0 and greater than γ, where γ is the sparsity threshold parameter that determines the proportion of non-zero weights to be retained and is adjusted according to the characteristics of medical data; |W t | represents taking the absolute value of all elements in the weight matrix W t ; sign(·) is the sign function that retains the weight direction to ensure that the weight update direction is consistent with the medical feature correlation (such as positively activating the lesion area).
[0078] Sparse weight matrix The goal is to generate a sparse and directionally stable sparse weight matrix through thresholding and sign function constraints to suppress noise interference.
[0079] Medical significance: Through ({w ∈ |W t ||w ≠ 0}, γ) > 0), sparse screening is performed to retain features that meet the threshold conditions, that is, features related to diseases (such as tumor texture, blood vessel morphology), and filter out irrelevant noise; sparsification reduces the sensitivity of the model to minor perturbations, meeting the requirements of medical authentication defense.
[0080] Calculate the projected weight matrix Including:
[0081]
[0082] Among them, is the weight gradient (obtained through backpropagation calculation) and is directly obtained from the optimizer (such as Adam, SGD); is the initial value of the projected weight matrix, and the initial value of the projected weight matrix is calculated by random initialization of the network;
[0083] χ is the residual term, representing the gap between the current weight and the ideal authentication condition, and the calculation method is: Among them, is the authentication weight matrix; The calculation process of the authentication weight matrix includes: Construct an optimization problem:
[0084]
[0085] Solve the optimization problem to obtain the authentication weight matrix Among them, F(t′) is the general term formula of the Fibonacci sequence, and t′ is the index of the iteration number.
[0086] π is the alignment metric between the projection direction and the gradient, reflecting whether the gradient direction conforms to the authentication constraint;
[0087] v is the adaptive step size scaling factor, which can be dynamically adjusted according to the historical gradient amplitude. If the recent gradient fluctuates greatly, then v is reduced to stabilize the update;
[0088] μ is the regularization coefficient, which represents balancing the influence of the projection direction and the gradient direction, and the default value is set to μ = 1.0, It can be optimized by gradient descent, and μ can be searched for a suitable μ in [10 -3 , 10 -2 , 10 -1 , 1] through grid search; cW t is the authentication constraint direction vector, and the calculation method is: That is, the constraint L ≤ Δ / ε max of the gradient direction.
[0089] Projection weight matrix The goal is to dynamically select the projection strategy according to the current state during weight update to ensure that the weight satisfies the authentication condition L ≤ Δ / ε max .
[0090] Medical significance:
[0091] Condition 1 (χ = 0, π ≥ 0): The weight already satisfies the authentication condition, and it is directly updated according to the gradient descent.
[0092] Condition 2 (χ > 0, πv ≥ χ): The weight deviates greatly from the authentication constraint, but the gradient direction is consistent with the constraint direction, and the step size is increased to accelerate convergence.
[0093] Condition 3 (χ > 0, πv < χ): The gradient direction is inconsistent with the constraint direction, and the gradient and the constraint direction are mixed for conservative update.
[0094] Other processing: Do not update the weight matrix and directly enter the next iteration to prevent illegal states (such as numerical overflow) and ensure the security of the medical model.
[0095] The above-described embodiments further illustrate in detail the object, technical solution and advantages of the present invention. It should be understood that the above-described embodiments are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, improvements, etc. made to the present invention within the spirit and principle of the present invention shall be included within the protection scope of the present invention.
Claims
1. A medical imaging diagnosis method based on Lipschitz constraints, characterized in that: include: Obtain medical imaging data, input the medical imaging data into a trained medical imaging diagnosis model, and obtain a diagnosis result; The training process of the medical imaging diagnosis model includes: S1. Obtain a medical imaging dataset, which includes clean samples and adversarial samples. S2. Input the samples in the medical imaging data set into the medical imaging diagnosis model to obtain the predicted probability of the samples in each category; the category with the largest predicted probability is the diagnosis result; S3. Calculate the loss function value according to the predicted probability of the sample in each category and the Lipschitz constraint; construct the certification conditions, and update the medical imaging diagnosis model according to the loss function value based on the certification conditions. When the loss function is minimized, the trained medical imaging diagnosis model is obtained.
2. A medical imaging diagnosis method based on Lipschitz constraints according to claim 1, characterized in that: Calculating the loss function value includes: calculating the comprehensive prediction probability f(x) of the largest prediction category and the second largest prediction category based on the prediction probability of the sample in each category max 、f(x) second , according to the comprehensive prediction probability f(x) max 、f(x) second The cross entropy loss functions of the maximum predicted category, the second largest predicted category, and the true category of the sample are calculated respectively, and the cross entropy loss functions of the maximum predicted category and the second largest predicted category are weightedly combined to obtain the final loss function value.
3. A medical imaging diagnosis method based on Lipschitz constraints according to claim 2, characterized in that: Calculate the comprehensive prediction probability f(x) of the maximum prediction category max Includes: Calculating the weight vector corresponding to the maximum predicted category in the last network layer of the medical imaging diagnosis model The weight vector corresponding to the true category of the sample The similarity measure between categories head_ji max , according to the weight vector corresponding to the true category of the sample Calculate the local Lipschitz constant and obtain the upper bound of the perturbation intensity ε max , according to the predicted probability f′(x) of the maximum predicted category max , similarity measure between categories head_ji max , the local Lipschitz constant and the upper bound of the perturbation strength ε max Calculate the comprehensive prediction probability f(x) of the maximum prediction category max .
4. The medical imaging diagnosis method based on Lipschitz constraint according to claim 1, characterized in that: The certification condition is L≤Δ / ε max ; where L is the local Lipschitz constant, Δ is the minimum confidence interval, and ε max is the upper bound of the disturbance intensity.
5. The medical imaging diagnosis method based on Lipschitz constraint according to claim 4, characterized in that: Updating the medical imaging diagnosis model includes: calculating the Lipschitz constant of the current iteration t of the medical imaging diagnosis model, if the Lipschitz constant is greater than Δ / ε max , then the sparse weight matrix is calculated according to the authentication conditions and the loss function value and the projection weight matrix For sparse weight matrix and the projection weight matrix Weighted combination, the updated weight matrix W of the medical imaging diagnosis model is obtained t+1 ; otherwise, do not update.
6. The medical imaging diagnosis method based on Lipschitz constraint according to claim 5, characterized in that: Compute sparse weight matrix include: Among them, W t is the weight matrix of the current iteration t of the entire medical imaging diagnosis model, ({w∈|W t ||w≠0},γ)>0) represents the matrix |W t The weight matrix consists of the weight elements w in | that are not equal to 0 and greater than γ, where γ is the sparsity control parameter, |W t | represents the weight matrix W t All elements in take their absolute values, and sign(·) is the sign function.
7. The medical imaging diagnosis method based on Lipschitz constraint according to claim 5, characterized in that: Calculate the projection weight matrix include: in, is the weight gradient, L MDB (W t ) is the loss function value, W t is the weight matrix of the current iteration t of the entire medical imaging diagnosis model, is the initial value of the projection weight matrix, χ is the residual term, which indicates the gap between the current weight matrix and the certification condition, π is the alignment measure between the projection direction and the gradient, v is the adaptive step size scaling factor, μ is the regularization coefficient, cW t Constraint direction vector for authentication condition.
8. The medical imaging diagnosis method based on Lipschitz constraint according to claim 7, characterized in that: The calculation process of the residual term χ includes: Construct the optimization problem: Solve the optimization problem and get the authentication weight matrix Calculate the projection weight matrix and the certification weight matrix The norm of the difference between , we get the residual term χ; where, is the weight vector corresponding to the true category of the sample in the last network layer of the medical image diagnosis model, F(t′) is the general formula of the Fibonacci sequence, and t′ is the index of the number of iterations.
9. The medical imaging diagnosis method based on Lipschitz constraint according to claim 8, characterized in that: Calculating the alignment metric π between the projection direction and the gradient includes: Calculating the authentication weight matrix With the projection weight matrix difference Calculate the weight gradient dW t Difference The similarity between the projection direction and the gradient is obtained.
10. The medical imaging diagnosis method based on Lipschitz constraint according to claim 7, characterized in that: Calculate the authentication constraint direction vector cW t include:
Citation Information
Patent Citations
Character and word dual-granularity confrontation and defense system and method for text classification model
CN114091568A
Integrated adversarial attack driven model robustness improvement method
CN118734931A
Remote sensing image recognition method and system based on deep learning
CN119339257A