Document Type

Thesis

Date of Award

5-31-2026

Degree Name

Master of Science in Computer Science - (M.S.)

Department

Computer Science

First Advisor

Cong Shi

Second Advisor

Lijing Wang

Third Advisor

Xuan Liu

Fourth Advisor

Mengnan Du

Abstract

This robustness of histopathology classification models under adversarial and real-world perturbations resembling clinical artifacts is being investigated.

Using whole-slide images from the CAMELYON17 cohort, four representative architectures—ResNet-18, ResNet-50, HIPT-2MLP, and ViT-B/16 —are benchmarked across controlled pixel-level distortions and artifact-like transformations. Adversarial methods include iterative Fast Gradient Sign, Projected Gradient Descent, Salt-and-Pepper noise, and the Adversarial Watermark—Stain Shift (AWSS). Three defense strategies—Randomized Smoothing, Adversarial Training, and an Artifact Detector—are evaluated for their ability to preserve diagnostic accuracy and model reliability. Structured perturbations consistently degrade performance, with transformer-based models showing the greatest sensitivity. The benchmark developed here offers a reproducible framework for assessing robustness at both tile and slide levels, supporting safer deployment of histopathology AI in clinical workflows.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.