• 文献检索
  • 文档翻译
  • 深度研究
  • 学术资讯
  • Suppr Zotero 插件Zotero 插件
  • 邀请有礼
  • 套餐&价格
  • 历史记录
应用&插件
Suppr Zotero 插件Zotero 插件浏览器插件Mac 客户端Windows 客户端微信小程序
定价
高级版会员购买积分包购买API积分包
服务
文献检索文档翻译深度研究API 文档MCP 服务
关于我们
关于 Suppr公司介绍联系我们用户协议隐私条款
关注我们

Suppr 超能文献

核心技术专利:CN118964589B侵权必究
粤ICP备2023148730 号-1Suppr @ 2026

文献检索

告别复杂PubMed语法,用中文像聊天一样搜索,搜遍4000万医学文献。AI智能推荐,让科研检索更轻松。

立即免费搜索

文件翻译

保留排版,准确专业,支持PDF/Word/PPT等文件格式,支持 12+语言互译。

免费翻译文档

深度研究

AI帮你快速写综述,25分钟生成高质量综述,智能提取关键信息,辅助科研写作。

立即免费体验

生物医学机器学习中基于梯度的增强攻击

Gradient-based enhancement attacks in biomedical machine learning.

作者信息

Rosenblatt Matthew, Dadashkarimi Javid, Scheinost Dustin

机构信息

Department of Biomedical Engineering, Yale University.

Department of Computer Science, Yale University.

出版信息

ArXiv. 2023 Aug 16:arXiv:2301.01885v2.

PMID:36713237
原文链接:https://pmc.ncbi.nlm.nih.gov/articles/PMC9882585/
Abstract

The prevalence of machine learning in biomedical research is rapidly growing, yet the trustworthiness of such research is often overlooked. While some previous works have investigated the ability of adversarial attacks to degrade model performance in medical imaging, the ability to falsely improve performance via recently-developed "enhancement attacks" may be a greater threat to biomedical machine learning. In the spirit of developing attacks to better understand trustworthiness, we developed two techniques to drastically enhance prediction performance of classifiers with minimal changes to features: 1) general enhancement of prediction performance, and 2) enhancement of a particular method over another. Our enhancement framework falsely improved classifiers' accuracy from 50% to almost 100% while maintaining high feature similarities between original and enhanced data (Pearson's ' > 0.99). Similarly, the method-specific enhancement framework was effective in falsely improving the performance of one method over another. For example, a simple neural network outperformed logistic regression by 17% on our enhanced dataset, although no performance differences were present in the original dataset. Crucially, the original and enhanced data were still similar ( = 0.99). Our results demonstrate the feasibility of minor data manipulations to achieve any desired prediction performance, which presents an interesting ethical challenge for the future of biomedical machine learning. These findings emphasize the need for more robust data provenance tracking and other precautionary measures to ensure the integrity of biomedical machine learning research. Code is available at https://github.com/mattrosenblatt7/enhancement_EPIMI.

摘要

机器学习在生物医学研究中的应用正迅速增加,但其研究的可信度却常常被忽视。虽然之前一些工作研究了对抗攻击在医学成像中降低模型性能的能力,但通过最近开发的“增强攻击”虚假提高性能的能力可能对生物医学机器学习构成更大威胁。本着开发攻击方法以更好理解可信度的精神,我们开发了两种技术,只需对特征进行最小更改就能大幅提高分类器的预测性能:1)预测性能的一般增强,以及2)一种特定方法相对于另一种方法的增强。我们的增强框架将分类器的准确率从50%虚假提高到近100%,同时保持原始数据和增强数据之间的高特征相似度(皮尔逊相关系数>0.99)。同样,特定方法增强框架在虚假提高一种方法相对于另一种方法的性能方面很有效。例如,在我们的增强数据集上,一个简单的神经网络比逻辑回归的性能高出17%,尽管在原始数据集中不存在性能差异。至关重要的是,原始数据和增强数据仍然相似(=0.99)。我们的结果证明了通过微小的数据操作实现任何所需预测性能的可行性,这给生物医学机器学习的未来带来了一个有趣的伦理挑战。这些发现强调了需要更强大的数据来源跟踪和其他预防措施,以确保生物医学机器学习研究的完整性。代码可在https://github.com/mattrosenblatt7/enhancement_EPIMI获取。

https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/5658c7f63a21/nihpp-2301.01885v2-f0003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/634e7925e1f6/nihpp-2301.01885v2-f0001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/db3fbe79a1bf/nihpp-2301.01885v2-f0002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/5658c7f63a21/nihpp-2301.01885v2-f0003.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/634e7925e1f6/nihpp-2301.01885v2-f0001.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/db3fbe79a1bf/nihpp-2301.01885v2-f0002.jpg
https://cdn.ncbi.nlm.nih.gov/pmc/blobs/4776/10443584/5658c7f63a21/nihpp-2301.01885v2-f0003.jpg

相似文献

1
Gradient-based enhancement attacks in biomedical machine learning.生物医学机器学习中基于梯度的增强攻击
ArXiv. 2023 Aug 16:arXiv:2301.01885v2.
2
Connectome-based machine learning models are vulnerable to subtle data manipulations.基于连接组的机器学习模型容易受到细微数据操纵的影响。
Patterns (N Y). 2023 May 15;4(7):100756. doi: 10.1016/j.patter.2023.100756. eCollection 2023 Jul 14.
3
Machine learning algorithms for outcome prediction in (chemo)radiotherapy: An empirical comparison of classifiers.机器学习算法在(放化疗)治疗结果预测中的应用:分类器的实证比较。
Med Phys. 2018 Jul;45(7):3449-3459. doi: 10.1002/mp.12967. Epub 2018 Jun 13.
4
Adversarial attacks against supervised machine learning based network intrusion detection systems.对抗攻击对基于监督机器学习的网络入侵检测系统的影响。
PLoS One. 2022 Oct 14;17(10):e0275971. doi: 10.1371/journal.pone.0275971. eCollection 2022.
5
Robust image classification against adversarial attacks using elastic similarity measures between edge count sequences.使用边缘计数序列之间的弹性相似性度量来进行对抗攻击的鲁棒图像分类。
Neural Netw. 2020 Aug;128:61-72. doi: 10.1016/j.neunet.2020.04.030. Epub 2020 Apr 30.
6
Adaptive Machine Learning Based Distributed Denial-of-Services Attacks Detection and Mitigation System for SDN-Enabled IoT.基于自适应机器学习的支持软件定义网络的物联网分布式拒绝服务攻击检测与缓解系统
Sensors (Basel). 2022 Mar 31;22(7):2697. doi: 10.3390/s22072697.
7
Defending the Defender: Adversarial Learning Based Defending Strategy for Learning Based Security Methods in Cyber-Physical Systems (CPS).捍卫防御者:基于对抗学习的防御策略,用于网络物理系统 (CPS) 中的基于学习的安全方法。
Sensors (Basel). 2023 Jun 9;23(12):5459. doi: 10.3390/s23125459.
8
A novel end-to-end classifier using domain transferred deep convolutional neural networks for biomedical images.一种使用域转移深度卷积神经网络的新型端到端生物医学图像分类器。
Comput Methods Programs Biomed. 2017 Mar;140:283-293. doi: 10.1016/j.cmpb.2016.12.019. Epub 2017 Jan 6.
9
Enhancing deep learning based classifiers with inpainting anatomical side markers (L/R markers) for multi-center trials.通过修复解剖学侧面标记(左/右标记)增强基于深度学习的分类器以用于多中心试验。
Comput Methods Programs Biomed. 2022 Jun;220:106705. doi: 10.1016/j.cmpb.2022.106705. Epub 2022 Feb 22.
10
Predicting asthma attacks in primary care: protocol for developing a machine learning-based prediction model.基层医疗中哮喘发作的预测:基于机器学习的预测模型的开发方案。
BMJ Open. 2019 Jul 9;9(7):e028375. doi: 10.1136/bmjopen-2018-028375.