Presentation 2022-06-24
Application of Adversarial Examples to Physical ECG Signals
Taiga Ono, Takeshi Sugawara, Jun Sakuma, Tatsuya Mori,
Abstract(in English) This work aims to assess the reality and feasibility of applying adversarial examples to attack cardiac diagnosis systems powered by machine learning algorithms. To this end, we introduce "adversarial beats", which are adversarial perturbations tailored specifically against classification systems designed to diagnose electrocardiograms (ECGs). We formulate an algorithm to generate adversarial beats, and evaluate their feasibility in a physical environment by designing a hardware attack. To the best of our knowledge, our work is the first in evaluating the proficiency of adversarial examples for ECGs in a physical setup. Our real-world experiments demonstrate that against an automated ECG diagnosis setup, we can leverage our proposed method to fake the presence of potential signs of cardiomyopathy with approximately 42.1% chance of success. We conclude that our proposed method can be leveraged by attackers to influence clinical decisions, which could be applied to fraudulent clinical transactions.
Keyword(in English) DNN / Adversarial Examples / Hardware
Paper # IA2022-11,ICSS2022-11
Date of Issue 2022-06-16 (IA, ICSS)

(in Japanese) (See Japanese page)
(in Japanese) (See Japanese page)
Title (in English) Application of Adversarial Examples to Physical ECG Signals
Date 2022-06-24
