arXiv:2412.18706cs.LGcs.AI2024-12

通过语义一致的病历扰动,暴露生存模型脆弱性。

SurvAttack: Black-Box Attack On Survival Models through Ontology-Informed EHR Perturbation

论文配图:SurvAttack: Black-Box Attack On Survival Models through Ontology-Informed EHR Perturbation
图 1 · 摘自论文原文
  • 设计贪心算法对纵向病历中的医疗编码进行隐蔽扰动
  • 扰动后模型预测排名准确率下降超过40%,显著降低性能
  • 适用于评估医疗模型鲁棒性,助力临床可解释性研究

生存分析(SA)模型广泛用于挖掘电子健康记录(EHR),以预测高危患者风险并优先处理。然而,其对抗攻击的脆弱性研究仍不充分。本文提出SurvAttack,一种基于语义一致、临床合理扰动的黑盒攻击框架,通过在患者长期EHR中实施细微但有效的医疗代码修改,破坏生存模型的预测性能。我们设计贪心算法生成多种对抗性操作,并基于敏感性、隐蔽性和临床意义的综合评分策略进行排序。该方法针对时间性生存紧迫度排序任务,实现高效攻击。实验显示,模型在扰动后预测排名准确率下降超40%,验证了其有效性。研究揭示了生存模型的潜在漏洞,为模型可解释性与医疗质量提升提供了新视角。

原文摘要 · Abstract (English)

Survival analysis (SA) models have been widely studied in mining electronic health records (EHRs), particularly in forecasting the risk of critical conditions for prioritizing high-risk patients. However, their vulnerability to adversarial attacks is much less explored in the literature. Developing black-box perturbation algorithms and evaluating their impact on state-of-the-art survival models brings two benefits to medical applications. First, it can effectively evaluate the robustness of models in pre-deployment testing. Also, exploring how subtle perturbations would result in significantly different outcomes can provide counterfactual insights into the clinical interpretation of model prediction. In this work, we introduce SurvAttack, a novel black-box adversarial attack framework leveraging subtle clinically compatible, and semantically consistent perturbations on longitudinal EHRs to degrade survival models' predictive performance. We specifically develop a greedy algorithm to manipulate medical codes with various adversarial actions throughout a patient's medical history. Then, these adversarial actions are prioritized using a composite scoring strategy based on multi-aspect perturbation quality, including saliency, perturbation stealthiness, and clinical meaningfulness. The proposed adversarial EHR perturbation algorithm is then used in an efficient SA-specific strategy to attack a survival model when estimating the temporal ranking of survival urgency for patients. To demonstrate the significance of our work, we conduct extensive experiments, including baseline comparisons, explainability analysis, and case studies. The experimental results affirm our research's effectiveness in illustrating the vulnerabilities of patient survival models, model interpretation, and ultimately contributing to healthcare quality.

生存分析对抗攻击医疗AI

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。