{"id":"https://openalex.org/W4413157643","doi":"https://doi.org/10.1109/cvpr52734.2025.02660","title":"Prompt2Perturb (P2P): Text-Guided Diffusion-Based Adversarial Attacks on Breast Ultrasound Images","display_name":"Prompt2Perturb (P2P): Text-Guided Diffusion-Based Adversarial Attacks on Breast Ultrasound Images","publication_year":2025,"publication_date":"2025-06-10","ids":{"openalex":"https://openalex.org/W4413157643","doi":"https://doi.org/10.1109/cvpr52734.2025.02660"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr52734.2025.02660","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52734.2025.02660","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5021111864","display_name":"Yasamin Medghalchi","orcid":"https://orcid.org/0009-0002-9415-2947"},"institutions":[{"id":"https://openalex.org/I141945490","display_name":"University of British Columbia","ror":"https://ror.org/03rmrcq20","country_code":"CA","type":"education","lineage":["https://openalex.org/I141945490"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Yasamin Medghalchi","raw_affiliation_strings":["University of British Columbia,Vancouver,BC,Canada"],"affiliations":[{"raw_affiliation_string":"University of British Columbia,Vancouver,BC,Canada","institution_ids":["https://openalex.org/I141945490"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5000174202","display_name":"Moein Heidari","orcid":"https://orcid.org/0000-0003-3676-0127"},"institutions":[{"id":"https://openalex.org/I141945490","display_name":"University of British Columbia","ror":"https://ror.org/03rmrcq20","country_code":"CA","type":"education","lineage":["https://openalex.org/I141945490"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Moein Heidari","raw_affiliation_strings":["University of British Columbia,Vancouver,BC,Canada"],"affiliations":[{"raw_affiliation_string":"University of British Columbia,Vancouver,BC,Canada","institution_ids":["https://openalex.org/I141945490"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5115460496","display_name":"Clayton Allard","orcid":null},"institutions":[{"id":"https://openalex.org/I141945490","display_name":"University of British Columbia","ror":"https://ror.org/03rmrcq20","country_code":"CA","type":"education","lineage":["https://openalex.org/I141945490"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Clayton Allard","raw_affiliation_strings":["University of British Columbia,Vancouver,BC,Canada"],"affiliations":[{"raw_affiliation_string":"University of British Columbia,Vancouver,BC,Canada","institution_ids":["https://openalex.org/I141945490"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053011888","display_name":"Leonid Sigal","orcid":"https://orcid.org/0000-0002-3942-2804"},"institutions":[{"id":"https://openalex.org/I141945490","display_name":"University of British Columbia","ror":"https://ror.org/03rmrcq20","country_code":"CA","type":"education","lineage":["https://openalex.org/I141945490"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Leonid Sigal","raw_affiliation_strings":["University of British Columbia,Vancouver,BC,Canada"],"affiliations":[{"raw_affiliation_string":"University of British Columbia,Vancouver,BC,Canada","institution_ids":["https://openalex.org/I141945490"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5015205742","display_name":"Ilker Hacihaliloglu","orcid":"https://orcid.org/0000-0003-3232-8193"},"institutions":[{"id":"https://openalex.org/I141945490","display_name":"University of British Columbia","ror":"https://ror.org/03rmrcq20","country_code":"CA","type":"education","lineage":["https://openalex.org/I141945490"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Ilker Hacihaliloglu","raw_affiliation_strings":["University of British Columbia,Vancouver,BC,Canada"],"affiliations":[{"raw_affiliation_string":"University of British Columbia,Vancouver,BC,Canada","institution_ids":["https://openalex.org/I141945490"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5021111864"],"corresponding_institution_ids":["https://openalex.org/I141945490"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.11673973,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"28564","last_page":"28574"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9901999831199646,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9901999831199646,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12296","display_name":"Autopsy Techniques and Outcomes","score":0.9128999710083008,"subfield":{"id":"https://openalex.org/subfields/2741","display_name":"Radiology, Nuclear Medicine and Imaging"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}},{"id":"https://openalex.org/T11515","display_name":"Bacillus and Francisella bacterial research","score":0.9103999733924866,"subfield":{"id":"https://openalex.org/subfields/1312","display_name":"Molecular Biology"},"field":{"id":"https://openalex.org/fields/13","display_name":"Biochemistry, Genetics and Molecular Biology"},"domain":{"id":"https://openalex.org/domains/1","display_name":"Life Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8116928339004517},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7017110586166382},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.49271371960639954},{"id":"https://openalex.org/keywords/diffusion","display_name":"Diffusion","score":0.44103673100471497},{"id":"https://openalex.org/keywords/breast-ultrasound","display_name":"Breast ultrasound","score":0.43737873435020447},{"id":"https://openalex.org/keywords/computer-vision","display_name":"Computer vision","score":0.42822685837745667},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.32882970571517944},{"id":"https://openalex.org/keywords/mammography","display_name":"Mammography","score":0.20137619972229004},{"id":"https://openalex.org/keywords/breast-cancer","display_name":"Breast cancer","score":0.1625974476337433},{"id":"https://openalex.org/keywords/medicine","display_name":"Medicine","score":0.13548418879508972},{"id":"https://openalex.org/keywords/physics","display_name":"Physics","score":0.07582974433898926},{"id":"https://openalex.org/keywords/internal-medicine","display_name":"Internal medicine","score":0.064657062292099}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8116928339004517},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7017110586166382},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.49271371960639954},{"id":"https://openalex.org/C69357855","wikidata":"https://www.wikidata.org/wiki/Q163214","display_name":"Diffusion","level":2,"score":0.44103673100471497},{"id":"https://openalex.org/C2777423100","wikidata":"https://www.wikidata.org/wiki/Q1888238","display_name":"Breast ultrasound","level":5,"score":0.43737873435020447},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.42822685837745667},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.32882970571517944},{"id":"https://openalex.org/C2780472235","wikidata":"https://www.wikidata.org/wiki/Q324634","display_name":"Mammography","level":4,"score":0.20137619972229004},{"id":"https://openalex.org/C530470458","wikidata":"https://www.wikidata.org/wiki/Q128581","display_name":"Breast cancer","level":3,"score":0.1625974476337433},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.13548418879508972},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.07582974433898926},{"id":"https://openalex.org/C126322002","wikidata":"https://www.wikidata.org/wiki/Q11180","display_name":"Internal medicine","level":1,"score":0.064657062292099},{"id":"https://openalex.org/C97355855","wikidata":"https://www.wikidata.org/wiki/Q11473","display_name":"Thermodynamics","level":1,"score":0.0},{"id":"https://openalex.org/C121608353","wikidata":"https://www.wikidata.org/wiki/Q12078","display_name":"Cancer","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cvpr52734.2025.02660","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52734.2025.02660","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/2","score":0.5400000214576721,"display_name":"Zero hunger"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320334593","display_name":"Natural Sciences and Engineering Research Council of Canada","ror":"https://ror.org/01h531d29"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":38,"referenced_works":["https://openalex.org/W1720890156","https://openalex.org/W1901129140","https://openalex.org/W2108598243","https://openalex.org/W2162884144","https://openalex.org/W2194775991","https://openalex.org/W2243397390","https://openalex.org/W2341106171","https://openalex.org/W2744692634","https://openalex.org/W2962770929","https://openalex.org/W2962785568","https://openalex.org/W2963446712","https://openalex.org/W2963857521","https://openalex.org/W2991372685","https://openalex.org/W2997532515","https://openalex.org/W3021182036","https://openalex.org/W3044053425","https://openalex.org/W3191453585","https://openalex.org/W4200594220","https://openalex.org/W4205991051","https://openalex.org/W4229054678","https://openalex.org/W4246141434","https://openalex.org/W4312933868","https://openalex.org/W4362556277","https://openalex.org/W4377695098","https://openalex.org/W4383558369","https://openalex.org/W4385573131","https://openalex.org/W4385805112","https://openalex.org/W4386076215","https://openalex.org/W4387885777","https://openalex.org/W4388491525","https://openalex.org/W4390872822","https://openalex.org/W4396532796","https://openalex.org/W4402715899","https://openalex.org/W4402753339","https://openalex.org/W4402774109","https://openalex.org/W4403422358","https://openalex.org/W4403649701","https://openalex.org/W4403649914"],"related_works":["https://openalex.org/W2502115930","https://openalex.org/W2482350142","https://openalex.org/W4246396837","https://openalex.org/W3126451824","https://openalex.org/W1561927205","https://openalex.org/W3191453585","https://openalex.org/W4297672492","https://openalex.org/W4310988119","https://openalex.org/W4285226279","https://openalex.org/W4288019534"],"abstract_inverted_index":{"Deep":[0],"neural":[1],"networks":[2],"(DNNs)":[3],"offer":[4],"significant":[5],"promise":[6],"for":[7,158],"improving":[8],"breast":[9,206],"cancer":[10],"diagnosis":[11],"in":[12,65,87,209,221],"medical":[13,69],"imaging.":[14],"However,":[15],"these":[16,58],"models":[17,59],"are":[18,60,217],"highly":[19],"susceptible":[20],"to":[21,77,123,141,227],"adversarial":[22,181,229],"attacks\u2014small,":[23],"imperceptible":[24,131],"changes":[25],"that":[26,129,167,178,197],"can":[27],"mislead":[28],"classifiers\u2014raising":[29],"critical":[30],"concerns":[31],"about":[32],"their":[33],"reliability":[34],"and":[35,211,223],"security.":[36],"Traditional":[37],"attacks":[38,50],"rely":[39],"on":[40,84,236],"fixed-norm":[41],"perturbations,":[42],"misaligning":[43],"with":[44],"human":[45],"perception.":[46],"In":[47,68,139],"contrast,":[48],"diffusion-based":[49],"require":[51],"pre-trained":[52],"models,":[53],"demanding":[54],"substantial":[55],"data":[56],"when":[57],"unavailable,":[61],"limiting":[62],"practical":[63],"use":[64],"data-scarce":[66],"scenarios.":[67],"imaging,":[70],"however,":[71],"this":[72],"is":[73,233],"often":[74],"unfeasible":[75],"due":[76],"the":[78,110,120,134,156,165,170,179,214],"limited":[79],"availability":[80],"of":[81,100],"datasets.":[82],"Building":[83],"recent":[85],"advancements":[86],"learnable":[88,117],"prompts,":[89],"we":[90,163],"propose":[91],"Prompt2Perturb":[92],"(P2P),":[93],"a":[94],"novel":[95],"language-guided":[96],"attack":[97,103,202],"method":[98,199],"capable":[99],"generating":[101],"meaningful":[102],"examples":[104,182],"driven":[105],"by":[106,150],"text":[107,121,153],"instructions.":[108],"During":[109],"prompt":[111,143],"learning":[112],"phase,":[113],"our":[114,146,198],"approach":[115],"leverages":[116],"prompts":[118],"within":[119],"encoder":[122],"create":[124],"subtle,":[125],"yet":[126],"impactful,":[127],"perturbations":[128],"remain":[130],"while":[132,176],"guiding":[133],"model":[135],"towards":[136],"targeted":[137],"outcomes.":[138],"contrast":[140],"current":[142],"learning-based":[144],"approaches,":[145],"P2P":[147],"stands":[148],"out":[149],"directly":[151],"updating":[152],"embeddings,":[154],"avoiding":[155],"need":[157],"retraining":[159],"diffusion":[160,172],"models.":[161],"Further,":[162],"leverage":[164],"finding":[166],"optimizing":[168],"only":[169],"early":[171],"steps":[173],"boosts":[174],"efficiency":[175],"ensuring":[177],"generated":[180,215],"incorporate":[183],"subtle":[184],"noise,":[185],"thus":[186],"preserving":[187],"ultrasound":[188,207],"image":[189],"quality":[190],"without":[191],"introducing":[192],"noticeable":[193],"artifacts.":[194],"We":[195],"show":[196],"outperforms":[200],"state-of-the-art":[201],"techniques":[203],"across":[204],"three":[205],"datasets":[208],"FID":[210],"LPIPS.":[212],"Moreover,":[213],"images":[216],"both":[218],"more":[219,224],"natural":[220],"appearance":[222],"effective":[225],"compared":[226],"existing":[228],"attacks.":[230],"Our":[231],"Code":[232],"publicly":[234],"available":[235],"GitHub.":[237]},"counts_by_year":[],"updated_date":"2025-12-28T23:10:05.387466","created_date":"2025-10-10T00:00:00"}
