All terms
Adversarial Robustness
Resilience of an ML model to inputs deliberately crafted to cause misclassification.
Reviewed by Christian Espinosa, Founder, Blue Goat CyberLast reviewed May 5, 2026
Definition
Adversarial examples - small, often imperceptible perturbations - can flip medical-imaging predictions. Robustness evaluation, input sanitization, and detection of out-of-distribution inputs are emerging expectations for safety-critical AI. What the regulation says
Regulators and standards bodies, such as the FDA in its AI/ML-based Medical Devices Action Plan and IMDRF in its guiding principles for AI/ML in medical devices, emphasize the need for robust AI systems. This includes addressing vulnerabilities to adversarial attacks to ensure the safety and effectiveness of AI-driven MedTech. While specific clauses directly addressing "adversarial robustness" are evolving, the principles of risk management in ISO 14971 and software validation in IEC 62304 implicitly cover the need to mitigate such risks.
What this means in practice
Particularly relevant for AI radiology and pathology devices where image acquisition is partially under attacker influence.Examples
- An AI ophthalmology device designed to detect diabetic retinopathy must be robust against subtle, intentionally crafted image perturbations that could cause it to miss pathology or flag healthy eyes as diseased.
- A pathology AI system used for cancer detection needs to be resilient to adversarial attacks that might alter digital slide images, leading to misclassification of tissue samples.
- An AI-powered diagnostic tool interpreting MRI scans should maintain its accuracy even if an attacker introduces imperceptible noise intended to alter the model's output, potentially influencing treatment decisions.
Common pitfalls
- •Assuming that general AI model validation is sufficient to cover adversarial robustness risks.
- •Failing to consider the potential for adversarial attacks throughout the entire lifecycle of a medical device.
- •Overlooking the importance of real-world data and expert review in identifying potential adversarial vulnerabilities.
- •Believing that simple input sanitization alone provides complete protection against sophisticated adversarial attacks.
- •Neglecting to update adversarial robustness evaluations as new attack techniques emerge or model changes occur.
Frequently asked questions
Adversarial robustness is crucial in MedTech because imperceptible perturbations can lead to misdiagnoses or incorrect treatment recommendations, posing significant patient safety risks. The consequences of AI failure in healthcare are much higher than in many other domains.
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsMore in Software & AI
· Same categorySoftware & AI
AAMI TIR45(TIR45)
AAMI Technical Information Report providing guidance on applying Agile software development practices within an IEC 62304-compliant medical device software lifecycle.
Software & AI
AI/ML-Enabled Medical Device
Medical device that uses artificial intelligence or machine learning to perform its intended use.
Software & AI
Algorithm Change Protocol(ACP)
The detailed procedural section of a PCCP that specifies how planned modifications to an AI/ML model will be developed, validated, and implemented.
Software & AI
Algorithmic Bias and Fairness
Systematic differences in model performance across demographic or clinical subgroups.
Cited by
Where this term appears across MedTech Terms.
Ecosystems (2)
Primary references
3 sourcesLink health: 3 verified· last checked 2026-06-20
FDA·1IMDRF·1MDCG·1
- 1
FDA - AI/ML-Enabled Medical DevicesVerifiedFDAfda.gov
- 2
IMDRF - Software as a Medical DeviceVerifiedIMDRFimdrf.org
- 3
MDCG Software GuidanceVerifiedMDCGhealth.ec.europa.eu
Inline markers like [1] jump to the matching reference above.