利用内存故障诱导视觉变压器模型误诊,隐蔽性强且成功率超80%
Hammering the Diagnosis: Rowhammer-Induced Stealthy Trojan Attacks on ViT-Based Medical Imaging
- 结合行翻转硬件攻击与神经后门,触发医疗影像模型错误判断
- 在MobileViT和SwinTransformer上攻击成功率达82.51%至92.56%
- 揭示硬件漏洞与AI安全的交叉风险,适合关注医疗AI安全的研究者
视觉变压器(ViTs)在医学图像分析中表现优异,广泛用于疾病检测、分割和分类。然而,其对大型注意力模型的依赖使其易受硬件级攻击。本文提出新型威胁模型Med-Hammer,将行翻转(Rowhammer)硬件故障注入与神经后门攻击结合,破坏基于ViT的医学影像系统完整性。实验表明,通过行翻转引发的恶意位翻转可触发植入的神经后门,导致医学影像中关键诊断(如肿瘤或病灶)被错误分类或抑制。在ISIC、Brain Tumor和MedMNIST等基准数据集上的大量测试显示,该攻击具有高度隐蔽性,且在MobileViT和SwinTransformer上的攻击成功率分别达到82.51%和92.56%。进一步研究发现,模型稀疏性、注意力权重分布及层特征数等架构特性显著影响攻击效果。研究揭示了硬件故障与深度学习安全在医疗应用中的关键交叉点,凸显了从模型架构到底层硬件需协同构建鲁棒防御的紧迫性。
原文摘要 · Abstract (English)
Vision Transformers (ViTs) have emerged as powerful architectures in medical image analysis, excelling in tasks such as disease detection, segmentation, and classification. However, their reliance on large, attention-driven models makes them vulnerable to hardware-level attacks. In this paper, we propose a novel threat model referred to as Med-Hammer that combines the Rowhammer hardware fault injection with neural Trojan attacks to compromise the integrity of ViT-based medical imaging systems. Specifically, we demonstrate how malicious bit flips induced via Rowhammer can trigger implanted neural Trojans, leading to targeted misclassification or suppression of critical diagnoses (e.g., tumors or lesions) in medical scans. Through extensive experiments on benchmark medical imaging datasets such as ISIC, Brain Tumor, and MedMNIST, we show that such attacks can remain stealthy while achieving high attack success rates about 82.51% and 92.56% in MobileViT and SwinTransformer, respectively. We further investigate how architectural properties, such as model sparsity, attention weight distribution, and the number of features of the layer, impact attack effectiveness. Our findings highlight a critical and underexplored intersection between hardware-level faults and deep learning security in healthcare applications, underscoring the urgent need for robust defenses spanning both model architectures and underlying hardware platforms.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。