为医疗AI设备设计前安全评估工具,防范潜在攻击风险。
Systems-Theoretic and Data-Driven Security Analysis in ML-enabled Medical Devices
- 基于公开召回数据构建威胁分析框架
- 提出一套用于预市场风险评估的实用工具集
- 适合医疗设备制造商与安全分析师参考
人工智能/机器学习在医疗设备中的融合正快速改变医疗行业,提升诊断与治疗能力。然而,复杂且常不透明的模型、广泛的互联性、与第三方外设的互操作性、互联网连接以及底层技术漏洞,共同扩大了攻击面,使威胁预防、检测和缓解变得困难。由于这些设备具有高度安全性要求,网络攻击可能导致模型误判,对患者安全构成严重威胁。因此,在设计阶段就确保设备安全至关重要。本文强调在上市前阶段应对医疗AI设备网络安全挑战的紧迫性。我们首先分析公开的设备召回、不良事件及已知漏洞数据,以理解此类设备的威胁格局及其对患者安全的影响。在此基础上,提出一套由我们开发的工具与技术,协助安全分析师进行全面的预市场风险评估。本工作旨在推动制造商将网络安全作为核心设计原则嵌入医疗AI设备,确保其对患者安全可靠。
原文摘要 · Abstract (English)
The integration of AI/ML into medical devices is rapidly transforming healthcare by enhancing diagnostic and treatment facilities. However, this advancement also introduces serious cybersecurity risks due to the use of complex and often opaque models, extensive interconnectivity, interoperability with third-party peripheral devices, Internet connectivity, and vulnerabilities in the underlying technologies. These factors contribute to a broad attack surface and make threat prevention, detection, and mitigation challenging. Given the highly safety-critical nature of these devices, a cyberattack on these devices can cause the ML models to mispredict, thereby posing significant safety risks to patients. Therefore, ensuring the security of these devices from the time of design is essential. This paper underscores the urgency of addressing the cybersecurity challenges in ML-enabled medical devices at the pre-market phase. We begin by analyzing publicly available data on device recalls and adverse events, and known vulnerabilities, to understand the threat landscape of AI/ML-enabled medical devices and their repercussions on patient safety. Building on this analysis, we introduce a suite of tools and techniques designed by us to assist security analysts in conducting comprehensive premarket risk assessments. Our work aims to empower manufacturers to embed cybersecurity as a core design principle in AI/ML-enabled medical devices, thereby making them safe for patients.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。