Systematic study examines adversarial vulnerability and enhances robustness in dental X-ray segmentation models.
Deep learning–based segmentation has become essential in computer-aided dental diagnosis and treatment planning. However, these models remain highly vulnerable to adversarial perturbations, like small and imperceptible changes in input images, which can drastically alter segmentation outputs and compromise clinical reliability. In this work, we present the first systematic study on adversarial vulnerability and robustness of deep learning models for panoramic dental X-ray segmentation. We curated a dataset of 995 panoramic images by combining 361 expert-annotated radiographs with 634 refined masks from the DENTEX 2023 challenge. Under identical training conditions, initially, we benchmarked 11 unique model variants, including five core architectures (Attention UNet, SegNet, Trans UNet, Vanilla UNet, and UNet++) and their corresponding ablations on training and preprocessing techniques. UNet++ emerged as the most practical backbone (clean IoU \(≈ 84%\) , Dice \(≈ 88%\) ) and subjected to a suite of white-box attacks with FGSM, I-FGSM, PGD, and DeepFool across perturbation ( \(ε ∈ \{0.01, 0.02, 0.05, 0.1\}\) ). Our results reveal that even minimal perturbations caused large performance drops, such as at \(ε = 0.01\) , IoU collapsed to 23.5% (0.851 to 0.649). To mitigate this fragility, we implemented a customized multi-attack adversarial defense strategy to ensure the model’s robustness, which preserved a modest clean-accuracy trade-off by increasing 14.9% (IoU 0.649 to 0.798) at \(ε = 0.01\) and 12.5% at \(ε = 0.02\) . Our qualitative and quantitative analyses demonstrate that the defended model produces more stable and anatomically consistent masks under attack and set the benchmark of adversarial robustness in dental image segmentation as an effective defense strategy for safety-critical clinical deployment.
No takes yet. Share an insight, caveat, or question.
Kohinoor et al. (2026) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: