PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
April 18, 2026Scientific Reports0 citationsOpen Access

Secure yet fragile: adversarial vulnerabilities of federated vision–language models in medical AI

AFAwal Ahmed FimeTSTasfia Zaman SamihaMHMd Zarif Hossain

Key Points

  • The aim is to assess the adversarial vulnerabilities of federated vision-language models in medical image analysis.
  • Evaluated CLIP-based vision-language models using four federated optimization strategies.
  • Tested robustness against adversarial attacks like FGSM, PGD, BIM, and MI-FGSM.
  • Compared the performance of two test-time defenses, Test-Time Counter-Attack and CLIPure.
  • Adversarial perturbations caused significant accuracy degradation in federated models.
  • Higher attack success rates were observed, especially with iterative attacks.
  • CLIPure provided more consistent improvements in mitigating adversarial effects across datasets.

Abstract

Abstract Vision–Language Models (VLMs) enable powerful multimodal reasoning for medical image analysis, while federated learning allows collaborative training across institutions without sharing patient data. However, the adversarial robustness of federated medical VLMs remains largely unexplored. This work systematically evaluates the vulnerability of CLIP-based VLMs trained with four federated optimization strategies, FedAvg, FedProx, FedPer, and FedBN, on multiple medical datasets. We assess robustness under FGSM, PGD, BIM, and MI-FGSM attacks at varying strengths and show that client-level adversarial perturbations propagate through federated aggregation, causing severe accuracy degradation and high attack success rates, specially under iterative attacks. We further benchmark two training-free test-time defenses, Test-Time Counter-Attack (TTC) and CLIPure, and demonstrate that both mitigate adversarial effects, with CLIPure providing more consistent improvements across datasets and attack intensities. These results highlight fundamental robustness limitations of federated medical VLMs and underscore the need for effective defense mechanisms in distributed clinical deployments.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Fime et al. (2026) studied this question.

synapsesocial.com/papers/69e3205140886becb653f6fehttps://doi.org/10.1038/s41598-026-48102-4
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Identifying significant features in adversarial attack detection framework using federated learning empowered medical IoT network security2025 · 8 citations
  2. 2A Survey of Attacks on Large Vision–Language Models: Resources, Advances, and Future Trends2025 · 37 citations
  3. 3Enhancing the Robustness of Vision-Language Foundation Models by Alignment Perturbation2025 · 5 citations
  4. 4Universal Adversarial Perturbations2017 · 2,744 citations
  5. 5CLIP is Strong Enough to Fight Back: Test-time Counterattacks towards Zero-shot Adversarial Robustness of CLIP2025 · 7 citations