Hard-Label Black-Box Adversarial Attack on Deep Electrocardiogram Classifier

Hard-Label Black-Box Adversarial Attack on Deep Electrocardiogram Classifier
复制标题

对深度心电图分类器的硬标签黑盒对抗攻击

DOI:
10.1145/3417312.3431827
复制
发表时间:
2020
期刊:
SecICPS '20: Proceedings of the 1st ACM International Workshop on Security and Safety for Intelligent Cyber-Physical Systems
影响因子:
--
通讯作者:
Srivastava, Mani
Srivastava, Mani
中科院分区:
--
文献类型:
--
作者:
Lam, Jonathan;Quan, Pengrui;Xu, Jiamin;Jeyakumar, Jeya Vikranth;Srivastava, Mani

文献摘要

参考文献

被引文献

相似文献

通过帮助诊断心律失常等心血管疾病(CVD)的过程,心电图(ECG)逐渐改善了现代医疗保健中自动化诊断系统的前景。近年来,深度神经网络(DNN)在分析心电数据方面有很好的应用前景,甚至在识别某些节律异常方面优于心血管专家。然而,DNN已被证明容易受到敌意攻击,这些攻击故意通过向输入添加扰动来损害模型。这一概念也适用于基于DNN的心电分类器,以前的工作是在白盒环境下生成这些对抗性攻击的,其中模型细节暴露给攻击者。然而,黑盒条件,即分类模型的架构和参数对于攻击者来说是未知的,大部分仍然没有被探索。因此,我们的目标是在黑盒和硬标签设置中愚弄心电分类器,在这种设置中,给定输入,攻击者只能看到最终预测的类别。我们对心脏病物理网络计算2017[12]数据库的DNN分类模型的攻击产生的心电数据集与对同一数据库的对抗性攻击的白盒版本几乎没有区别。我们的结果表明,在这种黑盒环境下,我们可以有效地生成对抗性的心电输入,这引起了人们对基于DNN的心电分类器在安全关键系统中的潜在应用的关注。
Through aiding the process of diagnosing cardiovascular diseases (CVD) such as arrhythmia, electrocardiograms (ECGs) have progressively improved prospects for an automated diagnosis system in modern healthcare. Recent years have seen the promising applications of deep neural networks (DNNs) in analyzing ECG data, even outperforming cardiovascular experts in identifying certain rhythm irregularities. However, DNNs have shown to be susceptible to adversarial attacks, which intentionally compromise the models by adding perturbations to the inputs. This concept is also applicable to DNN-based ECG classifiers and the prior works generate these adversarial attacks in a white-box setting where the model details are exposed to the attackers. However, the black-box condition, where the classification model's architecture and parameters are unknown to the attackers, remains mostly unexplored. Thus, we aim to fool ECG classifiers in the black-box and hard-label setting where given an input, only the final predicted category is visible to the attacker. Our attack on the DNN classification model for the PhysioNet Computing in Cardiology Challenge 2017 [12] database produced ECG data sets mostly indistinguishable from the white-box version of an adversarial attack on this same database. Our results demonstrate that we can effectively generate the adversarial ECG inputs in this black-box setting, which raises significant concerns regarding the potential applications of DNN-based ECG classifiers in security-critical systems.
DOI: 10.1016/j.disamonth.2012.12.002
发表时间: 2013-03-01
期刊: DM DISEASE-A-MONTH
影响因子: 4
作者:
Wadke, Rahul
通讯作者: Wadke, Rahul