\section{Related Work}
The use of one neural network to directly predict the confidence of another is an active topic of research \cite{confid-net,Fournel2021,obs-net,fs-net}. Similar to the ConfidNet \cite{confid-net}, our approach predicts confidence from activation maps. Our main contributions are an extension of that framework to image-level predictions of segmentation quality, and a novel training scheme that includes adversarial perturbations, increasing robustness to domain shifts.

Adversarial perturbations have been shown to be a useful strategy for learning segmentation quality previously \cite{obs-net}. However, that previous work made localized changes to street scenes, to improve robustness with respect to unknown objects. Our work is concerned with global changes that arise in medical images when changing acquisition devices or protocols, and therefore derives perturbations in a completely different way, from the confidence predictor itself.

Indirect confidence estimation methods often perform better than direct prediction in out of distribution scenarios. Unfortunately, they can be a computational burden during inference \cite{rca} or require specialized architectures, e.g., dropout layers for approximate Bayesian inference \cite{score-agreement}. As part of our experiments, we compare our approach against the latter in terms of quality and computational effort.

%%% Local Variables:
%%% mode: latex
%%% TeX-master: "../submission"
%%% End:
