arXiv:2510.23622cs.LGcs.CR2025-10被引 2

针对医疗AI的对抗攻击,提出更鲁棒的架构设计方法。

Adversarially-Aware Architecture Design for Robust Medical AI Systems

  • 通过实验证明皮肤病图像模型易受不可察觉的对抗攻击影响。
  • 对抗训练和知识蒸馏可降低攻击成功率但会损害正常数据表现。
  • 强调需结合技术、伦理与政策构建更公平可靠的医疗AI系统。

对抗攻击对医疗领域使用的AI系统构成严重威胁,可能导致模型产生危险误判,延误治疗或引发误诊。这些攻击通常对人眼不可察觉,尤其威胁弱势群体的患者安全。本研究通过在皮肤科数据集上的实证实验,揭示了对抗方法显著降低分类准确率的现象。通过详细的威胁建模、实验基准测试与模型评估,我们证明了该威胁的严重性以及对抗训练和知识蒸馏等防御手段的部分有效性。结果表明,尽管防御措施能降低攻击成功率,但仍需在模型在干净数据上的性能之间取得平衡。研究最终呼吁采取集成的技术、伦理与政策策略,以构建更具韧性与公平性的医疗AI系统。

原文摘要 · Abstract (English)

Adversarial attacks pose a severe risk to AI systems used in healthcare, capable of misleading models into dangerous misclassifications that can delay treatments or cause misdiagnoses. These attacks, often imperceptible to human perception, threaten patient safety, particularly in underserved populations. Our study explores these vulnerabilities through empirical experimentation on a dermatological dataset, where adversarial methods significantly reduce classification accuracy. Through detailed threat modeling, experimental benchmarking, and model evaluation, we demonstrate both the severity of the threat and the partial success of defenses like adversarial training and distillation. Our results show that while defenses reduce attack success rates, they must be balanced against model performance on clean data. We conclude with a call for integrated technical, ethical, and policy-based approaches to build more resilient, equitable AI in healthcare.

医疗AI对抗攻击模型鲁棒性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。