Injection of colored noise in medical images to protect against tampering
By introducing colored noise into medical images and removing it using neural networks, the problems of image tampering and unauthorized processing are solved, thus achieving the protection and verification of image authenticity.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-26
- Publication Date
- 2026-03-27
AI Technical Summary
Medical images are vulnerable to tampering and unauthorized processing during transmission and storage, and existing technologies lack effective protection measures.
Colored noise is introduced into medical images to generate noise with predefined statistical properties to enhance the images, and the noise is removed by a specially trained neural network to verify the image authenticity.
It enhances the ability to verify the authenticity of images, prevents unauthorized tampering and processing, and makes noise features difficult for third parties to identify.
Smart Images

Figure CN121753058A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The invention relates to a computer-implemented method of protecting medical images against tampering, a data processing apparatus, a computer program, and a computer readable storage medium. BACKGROUND
[0002] Especially in medical imaging, images acquired on specific hardware are often exported, for example in the form of DICOM images to a picture archiving and communication system, PACS.
[0003] However, malicious attacks against hospital networks have been described, in which neural networks are utilized to modify data during the transmission from the scanner to the PACS, introducing or removing lesions. Furthermore, images are stored and provided in picture archiving and communication systems, in principle enabling any third party to implement post-processing software, denoising or other image enhancement, such as super-resolution, on images available in the picture archiving and communication system. The application of digital signatures or watermarks to images is known, but rarely used.
[0004] The inventors of the present invention have thus found that it would be advantageous if there were an improved method of determining the authenticity of an image and / or verifying that an image cannot be manipulated or processed in any unauthorized manner. SUMMARY
[0005] It is an object of the present invention to provide an improved method of protecting images against tampering and unauthorized processing.
[0006] The object of the present invention is solved by the subject matter of the independent claims, wherein further embodiments are incorporated in the dependent claims.
[0007] The described embodiments similarly relate to a computer-implemented method of protecting medical images against tampering, a data processing apparatus, a computer program, and a computer readable storage medium. The further described embodiments can be combined in any possible way. Different combinations of embodiments can lead to synergistic effects, although this is not necessarily described in detail.
[0008] Furthermore, it should be noted that all embodiments of the invention with respect to a method can be carried out in the order of the steps described, however this does not have to be the only and necessary order of the steps of the method. The methods presented herein can be carried out in another order of the steps disclosed without departing from the respective method embodiments, unless explicitly stated otherwise herein.
[0009] According to a first aspect of the present application, a computer-implemented method of protecting medical images against tampering is provided. The method comprises the steps of receiving a medical image, generating colored noise, the colored noise having predefined statistical properties, augmenting the medical image with the colored noise, and providing the augmented medical image. The predefined statistical properties of the colored noise are characterized by a noise power spectrum.
[0010] Thus, a method and application of purposefully introducing colored noise in medical images is described. While it is easy to generate colored noise with selected statistical properties, it can be more difficult to determine specific noise characteristics and to remove such colored noise.
[0011] In recent years, denoising neural networks have shown great potential in medical imaging, outperforming traditional image denoising. Neural networks for image denoising can be trained on images in a very general way and can be applied to denoise any image or data with the same noise characteristics as used during training of the neural network.
[0012] However, it is important that when using a trained neural network for image denoising, it is applied to images exhibiting the correct noise characteristics, e.g. in the case of standard Cartesian magnetic resonance imaging, to images with complex independent Gaussian noise. Thus, previous applied image correction steps, e.g. geometric correction or frequency filters for handling gradient non-linearities in magnetic resonance imaging, make it more difficult to apply a denoising neural network or any network trained for further data processing, e.g. segmentation. However, the effects of these processing steps can be quite predictable and it is possible to incorporate their effects into the training process of the neural network.
[0013] In contrast, injecting additional specific noise with preferably variable noise characteristics has the potential to create a domain shift large enough to make the application of a neural network useless, which was not trained to remove this specific noise characteristic. The noise characteristics can vary from image to image and / or can vary within an image. Potential applications can include preventing third parties from applying a denoising neural network and ensuring authenticity of images in front of malicious attacks.
[0014] Thus, the presence of relevant noise patterns in the image can be used to detect tampering. Specifically, attacks on these images with added colored noise are likely to result in visible damage or degradation of the image, rather than the image being without any suspicious damage as the attacker would have hoped. Additionally or alternatively, attacks on these images can change the noise characteristics enough for the damage to be automatically detected, e.g. with a specifically trained neural network.
[0015] Thus, the use of noise with known statistical properties to augment medical images, and the ability to remove such noise with a properly trained network, can facilitate and increase the adoption of countermeasures in order to protect images from tampering and unauthorized handling.
[0016] Furthermore, such tamper-proofing measures are not apparent to third parties compared to, for example, the application of watermarks.
[0017] In embodiments of the invention, the step of augmenting the medical image with colored noise comprises adding the colored noise to the medical image.
[0018] In embodiments of the invention, the step of augmenting the medical image with colored noise comprises multiplying the colored noise with the medical image.
[0019] In embodiments of the invention, the step of generating the colored noise comprises modulating a frequency distribution of the medical image.
[0020] In embodiments of the invention, the frequency distribution is a spatial frequency distribution of the medical image.
[0021] In embodiments of the invention, modulating the frequency distribution of the medical image comprises multiplying the medical image with a weighting function in the acquisition domain of the medical image.
[0022] In embodiments of the invention, the step of generating the colored noise comprises using a stochastic random process.
[0023] In embodiments of the invention, the stochastic random process comprises a Markov chain.
[0024] In embodiments of the invention, the step of augmenting the medical image with colored noise comprises augmenting the medical image with the colored noise in image space, k-space, a coil image level of the medical image, or a transformed domain of the medical image. Thus, the colored noise can also be applied to any transformed domain, such as a wavelet transform, or any invertible, preferably unitary, transform.
[0025] In embodiments of the invention, the method comprises the step of removing measurement noise from the medical image prior to augmenting the medical image with the colored noise.
[0026] In embodiments of the invention, the step of augmenting the medical image with the colored noise is performed on a sub-region of the medical image or on the entire medical image.
[0027] In embodiments of the invention, the method comprises the step of removing the colored noise from the medical image that was enhanced with the colored noise in order to provide an image for further processing. The added noise can be removed by using a specifically trained neural network.
[0028] In embodiments of the invention, the method comprises the step of analyzing a previously enhanced medical image with colored noise with respect to noise characteristics, thereby verifying authenticity of the medical image.
[0029] According to another aspect of the invention, a data processing apparatus is provided, comprising means for performing the steps of the method according to any of the preceding embodiments.
[0030] According to another aspect of the invention, a computer program comprising instructions which, when the program is run by a computer, cause the computer to perform the steps of the method according to any of the preceding embodiments is provided.
[0031] According to another aspect of the invention, a computer computer-readable storage medium comprising instructions which, when run by a computer, cause the computer to perform the steps of the method according to any of the preceding embodiments is provided.
[0032] Hence, the benefits of any of the aspects described above apply equally to all other aspects, and vice versa.
[0033] In summary, the invention relates to a computer-implemented method of protecting a medical image against tampering. The method comprises generating a colored noise having predefined statistical properties, receiving a medical image, and enhancing the received medical image with the colored noise before providing an enhanced medical image.
[0034] One of the advantages of embodiments of the invention can be that authenticity of the image can be determined. Another advantage is that the protected image cannot be manipulated or processed in an unauthorized manner. Another advantage can be that the image can be protected against tampering by third parties.
[0035] These advantages are non-limiting and other advantages can be envisaged in the context of the present application.
[0036] The above aspects and embodiments will become apparent and elucidated from the exemplary embodiments described hereinafter. Exemplary embodiments of the present invention will be described hereinafter with reference to the following drawings: BRIEF DESCRIPTION OF DRAWINGS
[0037] Figure 1 A block diagram of a computer-implemented method for protecting a medical image against tampering according to embodiments of the invention is shown.
[0038] Figure 2 A flowchart of a computer-implemented method for protecting a medical image from tampering according to an embodiment of the present application is shown. List of reference signs 100 data processing device 110 medical image 111 enhanced medical image 120 colored noise DETAILED DESCRIPTION
[0039] Figure 1 A block diagram of a computer-implemented method for protecting a medical image 110 from tampering according to an embodiment of the present application is shown. The method comprises a step S110 of receiving a medical image 110, and a step S120 of generating a colored noise 120, the colored noise 120 comprising predefined statistical properties. The method comprises a further step S130 of enhancing the medical image 110 with the colored noise 120, and a step S140 of providing an enhanced medical image 111.
[0040] Figure 2 A flowchart of a computer-implemented method for protecting a medical image 110 from tampering according to an embodiment of the present application is shown. A medical image 110 is received, the medical image preferably being acquired by a medical imaging system for magnetic resonance imaging, computed tomography or ultrasound imaging. Next, at a predefined point in the image reconstruction chain, a colored noise 120 is intentionally injected into the image reconstruction chain. The colored noise 12 can be injected into the image, for example, by addition or multiplication. This can be done with or without first removing the noise originating from the uncorrelated complex Gaussian noise in the measurement domain. The resulting enhanced medical image 111 with added colored noise 120 will produce a similar visual appearance to the human eye as the medical image 110 that was not enhanced with the colored noise 120. However, it will be more difficult to remove the colored noise 120 that was intentionally added to the medical image 110, for example, using third-party denoising software that was not trained to remove this particular type of noise. The enhancing of the medical image 110 with the colored noise 120 can be performed in a data processing device 100, the device comprising units for performing the method steps according to the present application. The colored noise 120 can preferably be generated in the data processing device 100, the device enhancing the medical image 110 with the colored noise 120, but can also be generated in an external noise generator. By enhancing the medical image 110 with the colored noise 120, the medical image 110 is transformed into an enhanced medical image 111, which can be provided or saved into a picture archiving and communication system.
[0041] The colored noise 120 can be generated by a random statistical process at an appropriate point in the image generation or reconstruction chain. There are many ways known to create colored noise. One way is to modulate the spatial frequency distribution of the image, for example by multiplying it with a weighting function in the acquisition domain, which will result in noise that is correlated between neighboring voxels in the image space. Another way is to use a random stochastic process, for example a Markov chain, which can produce correlated samples.
[0042] The colored noise 120 can be added or multiplied to the medical image 110 in the image space, k-space, coil image level, or injected into any transform domain of the medical image 110.
[0043] Preferably, the original noise measured in the medical imaging system can be removed or subtracted before the colored noise 120 is added to the image.
[0044] Preferably, the colored noise can be added to certain regions of the image, similar to a fine watermark, which will enable the authenticity of the image to be determined, and / or verify whether the image has been tampered with. It can be considered to automatically remove the watermark of the colored noise that is only for display.
[0045] The colored noise added to the image is difficult to subtract for someone who does not know the statistical information of its generation. The images enhanced with colored noise look to the human eye as if there was no noise reduction of the measured noise, so they are still usable. However, full noise reduction can only be achieved after the additional colored noise injected into the image is removed.
[0046] If the authenticity of the image needs to be verified, the colored noise can be added to certain parts of the image or the entire image, or at least a watermark. It is important to recognize that the watermark of the colored noise can not be deterministic, so it can not be easily recognized or located by an outsider or third party. While it can be relatively easy to detect the presence of the colored noise, it is not easy to know the exact noise power spectrum used to generate the colored noise. However, to remove the colored noise, the exact noise power spectrum used for its generation needs to be known and a neural network needs to be trained to remove the corresponding noise. Once a suitable neural network is trained, it can be used again to remove the colored noise in the enhanced image.
[0047] While the application has been illustrated and described in detail in the drawings and foregoing description, such illustration and description are to be considered illustrative or exemplary only and not restrictive. The application is not limited to the disclosed embodiments. Other variations to the disclosed embodiments can be understood and effected by those skilled in the art in practising the claimed application, from a study of the drawings, the disclosure, and the appended claims.
[0048] In the claims, the word "comprising" does not exclude other elements or steps, and the words "a" or "an" do not exclude a plurality. In the claims, the term "consisting of means "including and excluding away any element other than the use of measures recited. Although specific measures are recited in mutually different dependent claims, this does not indicate that a combination of these measures can not be used advantageously. Any reference signs in the claims should not be construed as limiting the scope.
Claims
1. A computer-implemented method of protecting a medical image against tampering; the method comprising the steps of: receiving (SI 10) a medical image (110); generating (S120) colored noise (120), the colored noise (120) comprising a predefined statistical property; enhancing (S130) the medical image (110) with the colored noise (120); and providing (S140) an enhanced medical image (111) wherein the predefined statistical property of the colored noise (120) is characterized by a noise power spectrum.
2. The method of claim 1, wherein, The step of enhancing the medical image (110) with the colored noise (120) comprises adding the colored noise (120) to the medical image (110).
3. The method of claim 1, wherein, The step of enhancing the medical image (110) with the colored noise (120) comprises multiplying the colored noise (120) by the medical image (110).
4. The method according to any of the preceding claims, wherein, The step of generating the colored noise (120) comprises modulating a frequency distribution of the medical image (110).
5. The method of claim 4, wherein, The frequency distribution is a spatial frequency distribution of the medical image (110).
6. The method of any one of claims 4 or 5, wherein, Modulating the frequency distribution of the medical image (110) comprises multiplying the medical image (110) with a weighting function in the acquisition domain of the medical image (110).
7. The method of any one of claims 1 to 3, wherein, The step of generating the colored noise (120) comprises using a stochastic random process.
8. The method of claim 7, wherein, The stochastic random process comprises a Markov chain.
9. The method according to any of the preceding claims, wherein, The step of enhancing the medical image (110) with the colored noise (120) comprises enhancing the medical image (110) with the colored noise (120) in image space, in k-space, on a coil image level of the medical image, or in a transformed domain of the medical image.
10. The method according to any of the preceding claims, wherein, The method comprises the step of removing measurement noise from the medical image (110) before enhancing the medical image (110) with the colored noise (120).
11. The method according to any of the preceding claims, wherein, The step of enhancing the medical image (110) with the colored noise (120) is performed on a sub-region of the medical image (110) or on the entire medical image (110).
12. A data processing apparatus (100) comprising means for performing the steps of the method according to any one of claims 1 to 11.
13. A computer program comprising instructions which, when the program is run by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 11.
14. A computer-readable storage medium comprising instructions which, when executed by a computer, cause the computer to perform the steps of the method according to any one of claims 1 to 11.