攻击者仅用100-500样本即可攻破医疗AI,且检测常需6-12个月。
Data Poisoning Vulnerabilities Across Healthcare AI Architectures: A Security Threat Analysis
- 利用少量数据注入攻击各类医疗AI架构,包括深度学习与强化学习模型。
- 攻击成功率超60%,检测平均耗时6至12个月,部分攻击无法察觉。
- 适合关注医疗AI安全、系统设计及政策制定的研究者与从业者。
医疗AI系统面临严重数据投毒漏洞,现有防御与监管措施难以应对。我们分析了四类共八个攻击场景:针对卷积神经网络、大语言模型和强化学习代理的架构攻击;利用联邦学习与医疗文档系统的基础设施攻击;影响器官移植与危机分诊的资源分配攻击;以及针对商用基础模型的供应链攻击。研究发现,攻击者仅需100至500个样本即可在任意数据规模下破坏医疗AI,成功率常超过60%,检测时间估计为6至12个月,有时甚至无法察觉。医疗基础设施的分布式特性使内部人员可凭借常规权限发动攻击,技术门槛低。隐私法规如HIPAA与GDPR可能无意中庇护攻击者,因限制必要检测分析。供应链弱点允许单一受损供应商污染50至200家机构的模型。医学文书伪造案例(Medical Scribe Sybil)表明,通过合法临床流程的协同虚假就诊即可污染数据,无需系统入侵。现行法规未强制对抗鲁棒性测试,联邦学习反而因隐蔽溯源而加剧风险。建议采用多层防御策略,包括强制对抗测试、基于集成的检测、隐私保护安全机制及国际AI安全标准协调。同时质疑黑箱模型在高风险临床决策中的适用性,主张转向可解释、具备可验证安全性的系统。
原文摘要 · Abstract (English)
Healthcare AI systems face major vulnerabilities to data poisoning that current defenses and regulations cannot adequately address. We analyzed eight attack scenarios in four categories: architectural attacks on convolutional neural networks, large language models, and reinforcement learning agents; infrastructure attacks exploiting federated learning and medical documentation systems; critical resource allocation attacks affecting organ transplantation and crisis triage; and supply chain attacks targeting commercial foundation models. Our findings indicate that attackers with access to only 100-500 samples can compromise healthcare AI regardless of dataset size, often achieving over 60 percent success, with detection taking an estimated 6 to 12 months or sometimes not occurring at all. The distributed nature of healthcare infrastructure creates many entry points where insiders with routine access can launch attacks with limited technical skill. Privacy laws such as HIPAA and GDPR can unintentionally shield attackers by restricting the analyses needed for detection. Supply chain weaknesses allow a single compromised vendor to poison models across 50 to 200 institutions. The Medical Scribe Sybil scenario shows how coordinated fake patient visits can poison data through legitimate clinical workflows without requiring a system breach. Current regulations lack mandatory adversarial robustness testing, and federated learning can worsen risks by obscuring attribution. We recommend multilayer defenses including required adversarial testing, ensemble-based detection, privacy-preserving security mechanisms, and international coordination on AI security standards. We also question whether opaque black-box models are suitable for high-stakes clinical decisions, suggesting a shift toward interpretable systems with verifiable safety guarantees.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。