Evidence map›Paper›PMID 42225639›Full record

ArticleLight, science & applications2026

Universal and transferable attacks on pathology foundation models using microscopic perturbations.

Yuntian Wang, Xilin Yang, Che-Yung Shen, Shuhang Dong, Nir Pillar, Aydogan Ozcan

Abstract read
In one paragraph

Article in Light, science & applications, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Cited by 1 paper.

0numbers the graph read from it
0cells of the map it votes in
1citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

1 citing paper in PubMed.

  1. Review
4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

6 authors.

Yuntian Wang *Electrical and Computer Engineering Department, University of California, Los Angeles, CA, USA.
Xilin Yang *Electrical and Computer Engineering Department, University of California, Los Angeles, CA, USA.
Che-Yung ShenElectrical and Computer Engineering Department, University of California, Los Angeles, CA, USA.
Shuhang DongDepartment of Mathematics, University of California, Los Angeles, CA, USA.
Nir PillarDepartment of Pathology, Hadassah Hebrew University Medical Center, Jerusalem, Israel.
Aydogan OzcanElectrical and Computer Engineering Department, University of California, Los Angeles, CA, USA. ozcan@ucla.edu.ORCID http://orcid.org/0000-0002-0717-683X

Funding

TRD3: Data Analytics and Intelligent Systems (AI-ML-DL-Visualization)P41EB032840 · NIBIB · UNIVERSITY OF CALIFORNIA AT DAVIS · PI Griffith R. Harsh, Laura Marcu · 2022 to 2026
$6.7M
NIBIB NIH HHS P41 EB032840
6 · The paper itself

Abstract

The advent of foundation models initiated a paradigm shift in pathology and optical microscopy. However, these powerful systems also introduce vulnerabilities, making them susceptible to adversarial attacks. To shed light on these potential threats, here we introduce Universal and Transferable Adversarial Perturbations (UTAP) for pathology foundation models that reveal critical vulnerabilities. Optimized using deep learning, UTAP comprises a fixed and weak microscopic noise pattern that, when added to a pathology image, systematically disrupts the feature representation capabilities of foundation models. Therefore, UTAP induces performance drops in downstream tasks that utilize foundation models, including misclassification across a wide range of unseen data distributions. We demonstrate two key features of UTAP: (1) universality: its microscopic perturbation can be applied across diverse field-of-views independent of the dataset that UTAP was developed on, and (2) transferability: its perturbation can successfully degrade the performance of various external, black-box pathology foundation models-never seen before. These indicate that UTAP is not a dedicated attack associated with a specific foundation model or microscopy image dataset, but rather constitutes a broad threat to pathology foundation models and their applications. We evaluated UTAP across various state-of-the-art pathology foundation models on multiple datasets, causing significant drops in their performance with visually imperceptible microscopic modifications to the input images using a fixed noise pattern. The development of these potent attacks establishes a benchmark for model robustness evaluation, highlighting a need for advancing defense mechanisms to ensure the safe/reliable deployment of AI in pathology and optical microscopy.

Identifiers

PMID42225639
PMCPMC13226705

What Socratic holds

Textmetadata
LicenceCC BY
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the Socratic graph.