MedTech Terms
    The authoritative reference
    All terms

    Adversarial Robustness

    Resilience of an ML model to inputs deliberately crafted to cause misclassification.

    Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026

    Definition

    Adversarial examples - small, often imperceptible perturbations - can flip medical-imaging predictions. Robustness evaluation, input sanitization, and detection of out-of-distribution inputs are emerging expectations for safety-critical AI.
    What the regulation says
    Regulators and standards bodies, such as the FDA in its AI/ML-based Medical Devices Action Plan and IMDRF in its guiding principles for AI/ML in medical devices, emphasize the need for robust AI systems. This includes addressing vulnerabilities to adversarial attacks to ensure the safety and effectiveness of AI-driven MedTech. While specific clauses directly addressing "adversarial robustness" are evolving, the principles of risk management in ISO 14971 and software validation in IEC 62304 implicitly cover the need to mitigate such risks.

    What this means in practice

    Particularly relevant for AI radiology and pathology devices where image acquisition is partially under attacker influence.

    Examples

    • An AI ophthalmology device designed to detect diabetic retinopathy must be robust against subtle, intentionally crafted image perturbations that could cause it to miss pathology or flag healthy eyes as diseased.
    • A pathology AI system used for cancer detection needs to be resilient to adversarial attacks that might alter digital slide images, leading to misclassification of tissue samples.
    • An AI-powered diagnostic tool interpreting MRI scans should maintain its accuracy even if an attacker introduces imperceptible noise intended to alter the model's output, potentially influencing treatment decisions.
    Common pitfalls
    • Assuming that general AI model validation is sufficient to cover adversarial robustness risks.
    • Failing to consider the potential for adversarial attacks throughout the entire lifecycle of a medical device.
    • Overlooking the importance of real-world data and expert review in identifying potential adversarial vulnerabilities.
    • Believing that simple input sanitization alone provides complete protection against sophisticated adversarial attacks.
    • Neglecting to update adversarial robustness evaluations as new attack techniques emerge or model changes occur.

    Frequently asked questions

    Adversarial robustness is crucial in MedTech because imperceptible perturbations can lead to misdiagnoses or incorrect treatment recommendations, posing significant patient safety risks. The consequences of AI failure in healthcare are much higher than in many other domains.
    Grouped by theme
    Cited by

    Where this term appears across MedTech Terms.

    Primary references

    3 sources
    Link health: 3 verified· last checked 2026-06-20
    FDA·1IMDRF·1MDCG·1
    1. 1
      FDA - AI/ML-Enabled Medical Devices
      Verified
      FDAfda.gov
    2. 2
      IMDRF - Software as a Medical Device
      Verified
      IMDRFimdrf.org
    3. 3
      MDCG Software Guidance
      Verified
      MDCGhealth.ec.europa.eu

    Inline markers like [1] jump to the matching reference above.