EAAI Journal 2026 Journal Article
An output perturbation method based on few-shot learning with data augmentation for lung cancer classification
- Xiangfei Zhang
- Qingchen Zhang
Recently, using deep learning for the classification of computed tomography (CT) images has emerged as a promising approach for lung cancer classification. However, training deep learning models requires a large amount of data, and collecting a significant number of lung cancer CT images is a challenging task. Moreover, deep learning models are susceptible to privacy attacks, such as membership inference attacks (MIAs), which limit their application in the medical field. To address these issues, we propose a output perturbation method based on few-shot learning with data augmentation in this work. Specifically, to tackle the problem of insufficient data, we utilize data augmentation techniques to enrich the samples. We embed the original and augmented data using an encoder, and then perform a weighted fusion of these features. The fused features are subsequently input into a Multi-Layer Perceptron (MLP) to obtain the final embedded features. Furthermore, to prevent MIAs, we propose a differential privacy (DP)-based output perturbation strategy, which adaptively adds DP noise to the embedding vectors output by the MLP. Outputs with larger absolute values receive more noise, while those with smaller absolute values receive less noise. Experiments are conducted on two publicly available datasets, and the results showed that the proposed method in the DP scenario has significant advantages over the baseline method in lung cancer classification.