arXiv:2502.05214eess.IVcs.AI2025-02被引 4

用临床概念扰动生成肺部X光对抗样本,更真实地暴露医疗AI漏洞。

CoRPA: Adversarial Image Generation for Chest X-rays Using Concept Vector Perturbations and Generative Models

  • 基于临床概念向量扰动生成逼真误诊报告与图像。
  • 在MIMIC-CXR-JPG数据集上,模型对常规攻击抗性强但易被本方法攻破。
  • 适合关注医疗AI安全性的研究人员与临床部署团队。

用于医学影像分类的深度学习模型正广泛应用于辅助诊断工具,旨在提升诊断准确性、减轻医生负担并改善患者预后。然而,其对对抗攻击的脆弱性给患者安全带来重大风险。现有攻击方法多采用通用技术如模型查询或像素扰动生成对抗样本,难以充分反映因漏诊或误判临床特征导致的临床错误特性。本文提出概念驱动的报告扰动攻击(CoRPA),一种面向医疗影像领域的临床聚焦黑盒攻击框架。CoRPA利用临床概念生成与真实临床误诊场景高度一致的对抗性放射科报告和图像。我们在包含胸部X光片和放射科报告的MIMIC-CXR-JPG数据集上验证了该方法的有效性。评估结果显示,尽管深度学习模型对传统对抗攻击表现出较强鲁棒性,但在面对CoRPA的临床导向扰动时显著脆弱。这凸显了在医疗AI系统中关注领域特异性漏洞的重要性。通过引入专门的对抗攻击框架,本研究为开发可在真实世界中可靠部署的医疗AI模型奠定了基础,确保其在高风险临床环境中的安全应用。

原文摘要 · Abstract (English)

Deep learning models for medical image classification tasks are becoming widely implemented in AI-assisted diagnostic tools, aiming to enhance diagnostic accuracy, reduce clinician workloads, and improve patient outcomes. However, their vulnerability to adversarial attacks poses significant risks to patient safety. Current attack methodologies use general techniques such as model querying or pixel value perturbations to generate adversarial examples designed to fool a model. These approaches may not adequately address the unique characteristics of clinical errors stemming from missed or incorrectly identified clinical features. We propose the Concept-based Report Perturbation Attack (CoRPA), a clinically-focused black-box adversarial attack framework tailored to the medical imaging domain. CoRPA leverages clinical concepts to generate adversarial radiological reports and images that closely mirror realistic clinical misdiagnosis scenarios. We demonstrate the utility of CoRPA using the MIMIC-CXR-JPG dataset of chest X-rays and radiological reports. Our evaluation reveals that deep learning models exhibiting strong resilience to conventional adversarial attacks are significantly less robust when subjected to CoRPA's clinically-focused perturbations. This underscores the importance of addressing domain-specific vulnerabilities in medical AI systems. By introducing a specialized adversarial attack framework, this study provides a foundation for developing robust, real-world-ready AI models in healthcare, ensuring their safe and reliable deployment in high-stakes clinical environments.

医疗AI对抗攻击肺部X光概念扰动

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。