ORCID Identifier(s)

0009-0007-4586-627X

Graduation Semester and Year

Spring 2026

Language

English

Document Type

Thesis

Degree Name

Master of Science in Biomedical Engineering

Department

Bioengineering

First Advisor

Dr. Jacob Luber

Second Advisor

Dr. Justyn Jaworski

Third Advisor

Dr. Xi Zhu

Abstract

This study investigates adversarial vulnerabilities in deep learning models for biomedical time-series classification across two clinically important modalities: electrocardiography (ECG) and electroencephalography (EEG). Using the MIT-BIH Arrhythmia and CHB-MIT seizure datasets, I evaluate time-domain attacks (FGSM, PGD), Fourier-domain constrained attacks, and learned spectral perturbations designed to reveal modality-specific sensitivity patterns. Across both tasks, a consistent trend emerges low-frequency components (0–5 Hz) constitute a dominant axis of adversarial vulnerability, with perturbations in this range producing the steepest degradation in classification performance. In ECG models, protecting the physiologically relevant QRS band (5–20 Hz) significantly improves robustness, whereas EEG models remain highly sensitive to delta-band perturbations even under strict spectral constraints. Learned spectral masks and gradient-based analyses converge on similar frequency profiles, indicating that deep networks rely heavily on slow-wave structure for decision-making. Additionally, minority classes exhibit disproportionately higher susceptibility to adversarial perturbations. These findings demonstrate that adversarial vulnerabilities in biomedical time-series models are closely tied to underlying signal physiology and spectral composition. The results show the need for frequency-aware defenses, physiologically informed architectures, and robust training frameworks to ensure reliable deployment of neural systems in clinical environments.

Keywords

Adversarial Machine Learning, EEG Signal Classification, Epileptic Seizure Detection, Spectral Adversarial Attacks, Biomedical Time-Series Analysis, Deep Learning for Healthcare, Frequency-Domain Robustness, Electroencephalography (EEG), Explainable Artificial Intelligence, Robust Neural Networks

Disciplines

Bioimaging and Biomedical Optics | Biomedical Informatics | Disease Modeling | Other Biomedical Engineering and Bioengineering | Vision Science

License

Creative Commons Attribution 4.0 International License
This work is licensed under a Creative Commons Attribution 4.0 International License.

Comments

I would like to express my deepest gratitude to Dr. Jacob Luber, my thesis advisor and professor at the University of Texas at Arlington, for his invaluable guidance, insightful feedback, and unwavering support throughout the course of this research.

I am also sincerely thankful to Dr. Justyn Jaworski and Dr. Xi Zhu for serving on my thesis committee.

My appreciation extends to Dr. Khosrow Behbehani, whose support in identifying and providing access to the initial datasets and pretrained model weights made the early stages of this project possible.

I would also like to acknowledge Jai Prakash Veerla, my Ph.D. mentor, for his continuous encouragement, technical guidance, and mentorship.

My Parents Sanjay and Mamta Tiwari for their tremendous encouragement and support.

Finally, I am grateful to the Department of Bioengineering at the University of Texas at Arlington for providing the academic environment and resources necessary to carry out this research.

Share

COinS
 
 

To view the content in your browser, please download Adobe Reader or, alternately,
you may Download the file to your hard drive.

NOTE: The latest versions of Adobe Reader do not support viewing PDF files within Firefox on Mac OS and if you are using a modern (Intel) Mac, there is no official plugin for viewing PDF files within the browser window.