arXiv:2508.17215cs.LGcs.AI2025-08被引 4

提出模拟医疗多模态RAG系统漏洞的攻击框架,揭示其安全风险。

How to make Medical AI Systems safer? Simulating Vulnerabilities, and Threats in Multimodal Medical RAG System

  • 构建半开放环境,注入跨模态矛盾图像文本对进行攻击
  • 在两个数据集上使F1分数下降最高达27.66%,最低降至51.36%
  • 适合关注医疗AI安全、多模态一致性验证的研究者

大型视觉语言模型(LVLM)结合检索增强生成(RAG)正被广泛用于医疗AI,以通过外部临床图文检索提升事实准确性。但这种依赖带来了显著攻击面。我们提出MedThreatRAG,一种新型多模态投毒框架,通过注入对抗性图文对系统性探测医疗RAG系统的漏洞。关键创新在于构建模拟半开放攻击环境,模仿允许用户或管道定期更新知识库的真实医疗系统。在此设定中,我们引入并强调跨模态冲突注入(CMCI),在医学图像与其配对报告间嵌入细微语义矛盾。这些不一致破坏跨模态对齐,导致检索与生成性能下降,同时足够合理以逃避常规过滤机制。尽管包含基础文本与视觉攻击作为完整性补充,CMCI表现最严重。在IU-Xray和MIMIC-CXR QA任务上的评估显示,MedThreatRAG使答案F1分数最多降低27.66%,并将LLaVA-Med-1.5的F1率降至最低51.36%。研究揭示了临床RAG系统中的根本安全缺口,强调亟需威胁感知设计与鲁棒的多模态一致性检查。最后,我们总结出一套简明指南,指导未来多模态医疗RAG系统的安全开发。

原文摘要 · Abstract (English)

Large Vision-Language Models (LVLMs) augmented with Retrieval-Augmented Generation (RAG) are increasingly employed in medical AI to enhance factual grounding through external clinical image-text retrieval. However, this reliance creates a significant attack surface. We propose MedThreatRAG, a novel multimodal poisoning framework that systematically probes vulnerabilities in medical RAG systems by injecting adversarial image-text pairs. A key innovation of our approach is the construction of a simulated semi-open attack environment, mimicking real-world medical systems that permit periodic knowledge base updates via user or pipeline contributions. Within this setting, we introduce and emphasize Cross-Modal Conflict Injection (CMCI), which embeds subtle semantic contradictions between medical images and their paired reports. These mismatches degrade retrieval and generation by disrupting cross-modal alignment while remaining sufficiently plausible to evade conventional filters. While basic textual and visual attacks are included for completeness, CMCI demonstrates the most severe degradation. Evaluations on IU-Xray and MIMIC-CXR QA tasks show that MedThreatRAG reduces answer F1 scores by up to 27.66% and lowers LLaVA-Med-1.5 F1 rates to as low as 51.36%. Our findings expose fundamental security gaps in clinical RAG systems and highlight the urgent need for threat-aware design and robust multimodal consistency checks. Finally, we conclude with a concise set of guidelines to inform the safe development of future multimodal medical RAG systems.

医疗AIRAG安全多模态对抗攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。