title: "adverSCarial, generate and analyze the vulnerability of scRNA-seq classifiers to adversarial attacks" shorttitle: "adverSCarial" author: Ghislain FIEVET package: adverSCarial abstract: > adverSCarial is an R Package designed for generating and analyzing the vulnerability of scRNA-seq classifiers to adversarial attacks. The package is versatile and provides a format for integrating any type of classifier. It offers functions for studying and generating two types of attacks, single gene attack and max change attack. The single gene attack involves making a small modification to the input to alter the classification. The max change attack involves making a large modification to the input without changing its classification. The package provides a comprehensive solution for evaluating the robustness of scRNA-seq classifiers against adversarial attacks. vignette: > %\VignetteIndexEntry{Vign04_advRandWalkMinChange} %\VignetteEngine{knitr::knitr} %\VignetteEncoding{UTF-8} # advRandWalkMinChange The `CHETAH` classifier is not vulnerable to one gene attack on `DC`cluster. We can use the `advRandWalkMinChange` function to generate a more complex attack, still looking for a minimum change in the input. We will find a list of genes suscpetibles to move the classification by using the `findMarkers` function from `scran`. Then we will use the `advRandWalkMinChange` function to shorten the list as much as possible. # Load data ```r library(adverSCarial) library(TENxPBMCData) library(CHETAH) library(scater) library(scran) library(stringr) ``` We get two pbmc datasets, *train_3k* to train the CHETAH classifier, and *test_4k* to run the adverSCarial functions. ```r train_3k <- TENxPBMCData(dataset = "pbmc3k") test_4k <- TENxPBMCData(dataset = "pbmc4k") # Convert from ensemble id to hgnc symbol test_4k <- sceConvertToHGNC(test_4k) train_3k <- sceConvertToHGNC(train_3k) cell_types_3k <- system.file("extdata", "pbmc3k_cell_types.tsv", package="adverSCarial") cell_types_3k <- read.table(cell_types_3k, sep="\t") colData(train_3k)$celltypes <- cell_types_3k$cell_type colnames(train_3k) <- colData(train_3k)[['Barcode']] colnames(test_4k) <- colData(test_4k)[['Barcode']] ``` Annotation of the *test_4k* dataset with CHETAH, and processing of the SingleCellExperiment object. ```r input <- CHETAHclassifier(input = test_4k, ref_cells = train_3k) input <- Classify(input = input, 0.00001) colData(test_4k)$celltypes <- input$celltype_CHETAH test_4k <- logNormCounts(test_4k) dec <- modelGeneVar(test_4k) hvg <- getTopHVGs(dec, prop=0.1) test_4k <- runPCA(test_4k, ncomponents=25, subset_row=hvg) test_4k <- runUMAP(test_4k, dimred = 'PCA') ``` ```r CHETAHClassifier <- function(expr, clusters, target){ reference_3k <- train_3k input <- CHETAHclassifier(input = expr, ref_cells = reference_3k) input <- Classify(input = input, 0.01) final_predictions = input$celltype_CHETAH[clusters == target] ratio <- as.numeric(sort(table(final_predictions), decreasing = TRUE)[1]) / sum(as.numeric(sort(table(final_predictions), decreasing = TRUE))) predicted_class <- names(sort(table(final_predictions), decreasing = TRUE)[1]) if ( ratio < 0.3){ predicted_class <- "NA" } c(predicted_class, ratio) } ``` # Advanced attacks with `advRandWalkMinChange` We use the `advRandWalkMinChange` function to generate a complex attack, looking for a minimum change of several genes in the input. First step is to look for a list of genes suscpetibles to move the classification. We get this list by using the `findMarkers` function from `scran`. ```r markers <- c("IL7R", "CCR7", "CD14", "LYZ", "S100A4", "MS4A1", "CD8A", "FCGR3A", "MS4A7", "GNLY", "NKG7", "FCER1A", "CST3", "PPBP") test_4k_subset <- test_4k[, test_4k$celltypes %in% c("CD14+ Mono", "DC")] fm_t4k <- findMarkers(test_4k_subset, test_4k_subset$celltypes) genes_4walk <- rownames(fm_t4k[['DC']][abs(fm_t4k[['DC']]$summary.logFC)>1,]) # Remove the officiel markers from the candidates genes_4walk <- genes_4walk[!genes_4walk %in% markers] genes_4walk ``` ``` ## [1] "HLA-DRA" "S100A12" "HLA-DQB1" "HLA-DPA1" "HLA-DPB1" "HLA-DRB1" ## [7] "S100A8" "HLA-DQA1" "S100A9" "CD74" "VCAN" "HLA-DMA" ## [13] "CTSS" "FTL" "FCN1" "TYROBP" "NEAT1" ``` Then we define a list of modifications to test: ```r modifications <- list() modifications[[1]] <- list("perc99") modifications[[2]] <- list("perc1") ``` Then we process to a random walk parameter search on these genes and these modifications: ```r rand_walk_min_change <- advRandWalkMinChange(test_4k, colData(test_4k)$celltypes, "DC", CHETAHClassifier, genes=genes_4walk, modifications=modifications, walkLength=15, argForClassif = 'SingleCellExperiment') head(rand_walk_min_change) ``` ``` ## DataFrame with 6 rows and 22 columns ## prediction odd genesModified typeModified iteration HLA.DRA ## ## 1 UNDETERMINED 0.484375 2 TRUE 15 NA ## 2 CD14+ Mono 0.578125 3 TRUE 14 NA ## 3 UNDETERMINED 0.5 4 TRUE 13 NA ## 4 UNDETERMINED 0.5 5 TRUE 11 perc99 ## 5 CD14+ Mono 0.5 7 TRUE 10 perc99 ## 6 UNDETERMINED 0.59375 8 TRUE 9 perc99 ## S100A12 HLA.DQB1 HLA.DPA1 HLA.DPB1 HLA.DRB1 S100A8 ## ## 1 NA perc1 perc1 NA NA NA ## 2 NA perc1 perc1 NA NA perc99 ## 3 NA perc1 perc1 NA NA perc1 ## 4 NA perc1 perc1 NA NA perc1 ## 5 NA perc1 perc1 NA NA perc1 ## 6 NA perc1 perc1 NA perc1 perc1 ## HLA.DQA1 S100A9 CD74 VCAN HLA.DMA CTSS ## ## 1 NA NA NA NA NA NA ## 2 NA NA NA NA NA NA ## 3 NA NA NA NA perc1 NA ## 4 NA NA NA NA perc1 NA ## 5 NA NA perc1 perc1 perc1 NA ## 6 NA NA perc1 perc1 perc1 NA ## FTL FCN1 TYROBP NEAT1 ## ## 1 NA NA NA NA ## 2 NA NA NA NA ## 3 NA NA NA NA ## 4 NA NA NA NA ## 5 NA NA NA NA ## 6 NA NA NA NA ``` The first line of `rand_walk_min_change` contains the parameter for the attack: ```r best_results <- rand_walk_min_change[1,] best_results <- as.data.frame(best_results[6:ncol(best_results)]) best_results <- best_results[,best_results!="NA"] best_results ``` ``` ## HLA.DQB1 HLA.DPA1 ## 1 perc1 perc1 ``` Then we modify the rna expression matrix to fool the classifier: ```r min_change_attack_rna_matrix <- test_4k for ( i in seq_len(length(colnames(best_results)))){ gene2modif <- colnames(best_results)[i] gene2modif <- str_replace(gene2modif, "\\.", "-") modif <- best_results[1,i] min_change_attack_rna_matrix <- advModifications(min_change_attack_rna_matrix, gene2modif, colData(test_4k)$celltypes, "DC", advMethod=modif, argForClassif="SingleCellExperiment") } ``` And we check it successfully changed the classification. ```r res_classif <- CHETAHClassifier(min_change_attack_rna_matrix, colData(test_4k)$celltypes, "DC") ``` ```r res_classif ``` ``` ## [1] "UNDETERMINED" "0.484375" ``` ```r sessionInfo() ``` ``` ## R version 4.3.0 (2023-04-21) ## Platform: x86_64-pc-linux-gnu (64-bit) ## Running under: Ubuntu 22.04.1 LTS ## ## Matrix products: default ## BLAS: /usr/lib/x86_64-linux-gnu/blas/libblas.so.3.10.0 ## LAPACK: /usr/lib/x86_64-linux-gnu/lapack/liblapack.so.3.10.0 ## 