提出模拟医疗多模态RAG系统漏洞的攻击框架,揭示其安全风险。
How to make Medical AI Systems safer? Simulating Vulnerabilities, and Threats in Multimodal Medical RAG System
- 构建半开放环境,注入跨模态矛盾图像文本对进行攻击
- 在两个数据集上使F1分数下降最高达27.66%,最低降至51.36%
- 适合关注医疗AI安全、多模态一致性验证的研究者
大型视觉语言模型(LVLM)结合检索增强生成(RAG)正被广泛用于医疗AI,以通过外部临床图文检索提升事实准确性。但这种依赖带来了显著攻击面。我们提出MedThreatRAG,一种新型多模态投毒框架,通过注入对抗性图文对系统性探测医疗RAG系统的漏洞。关键创新在于构建模拟半开放攻击环境,模仿允许用户或管道定期更新知识库的真实医疗系统。在此设定中,我们引入并强调跨模态冲突注入(CMCI),在医学图像与其配对报告间嵌入细微语义矛盾。这些不一致破坏跨模态对齐,导致检索与生成性能下降,同时足够合理以逃避常规过滤机制。尽管包含基础文本与视觉攻击作为完整性补充,CMCI表现最严重。在IU-Xray和MIMIC-CXR QA任务上的评估显示,MedThreatRAG使答案F1分数最多降低27.66%,并将LLaVA-Med-1.5的F1率降至最低51.36%。研究揭示了临床RAG系统中的根本安全缺口,强调亟需威胁感知设计与鲁棒的多模态一致性检查。最后,我们总结出一套简明指南,指导未来多模态医疗RAG系统的安全开发。
原文摘要 · Abstract (English)
Large Vision-Language Models (LVLMs) augmented with Retrieval-Augmented Generation (RAG) are increasingly employed in medical AI to enhance factual grounding through external clinical image-text retrieval. However, this reliance creates a significant attack surface. We propose MedThreatRAG, a novel multimodal poisoning framework that systematically probes vulnerabilities in medical RAG systems by injecting adversarial image-text pairs. A key innovation of our approach is the construction of a simulated semi-open attack environment, mimicking real-world medical systems that permit periodic knowledge base updates via user or pipeline contributions. Within this setting, we introduce and emphasize Cross-Modal Conflict Injection (CMCI), which embeds subtle semantic contradictions between medical images and their paired reports. These mismatches degrade retrieval and generation by disrupting cross-modal alignment while remaining sufficiently plausible to evade conventional filters. While basic textual and visual attacks are included for completeness, CMCI demonstrates the most severe degradation. Evaluations on IU-Xray and MIMIC-CXR QA tasks show that MedThreatRAG reduces answer F1 scores by up to 27.66% and lowers LLaVA-Med-1.5 F1 rates to as low as 51.36%. Our findings expose fundamental security gaps in clinical RAG systems and highlight the urgent need for threat-aware design and robust multimodal consistency checks. Finally, we conclude with a concise set of guidelines to inform the safe development of future multimodal medical RAG systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。