USENIX Security2019Top-tier venue
CT-GAN: Malicious Tampering of 3D Medical Imagery using Deep Learning
Yisroel Mirsky, Tom Mahler, Ilan Shelef, Yuval Elovici
Abstract
In 2018, clinics and hospitals were hit with numerous attacks leading to significant data breaches and interruptions in medical services. An attacker with access to medical records can do much more than hold the data for ransom or sell it on the black market. In this paper, we show how an attacker can use deep-learning to add or remove evidence of medical conditions from volumetric (3D) medical scans. An attacker may perform this act in order to stop a political candidate, sabotage research, commit insurance fraud, perform an act of terrorism, or even commit murder. We implement the attack using a 3D conditional GAN and show how the framework (CT-GAN) can be automated. Although the body is complex and 3D medical scans are very large, CT-GAN achieves realistic results which can be executed in milliseconds. To evaluate the attack, we focused on injecting and removing lung cancer from CT scans. We show how three expert radiologists and a state-of-the-art deep learning AI are highly susceptible to the attack. We also explore the attack surface of a modern radiology network and demonstrate one attack vector: we intercepted and manipulated CT scans in an active hospital network with a covert penetration test. Demo video: this https URL Source code: this https URL
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b0cb69f0-b676-4de3-a79c-5286fe69c021Cited by top-tier papers5
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition SystemsShangyu Xie, Han Wang, Yu Kong, Yuan HongS&P 2022 · 32 citations
- Correction-based Defense Against Adversarial Video Attacks via Discretization-Enhanced Video Compressive SensingWei Song, Cong Cong, Haonan Zhong, Jingling XueUSENIX Security 2024 · 8 citations
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- Synthetic Learning: Learn From Distributed Asynchronized Discriminator GAN Without Sharing Medical Image DataQi Chang, Hui Qu, Yikai Zhang, Mert R. Sabuncu et al.CVPR 2020
- XCheck: Verifying Integrity of 3D Printed Patient-Specific Devices via Computing TomographyZhiyuan Yu, Yuanhaur Chang, Shixuan Zhai, Nicholas Deily et al.USENIX Security 2023
Builds on1
Related papers
- ConfounderGAN: Protecting Image Data Privacy with Causal ConfounderQi Tian, Kun Kuang, Kelu Jiang, Furui Liu et al.NeurIPS 2022 · 11 citations
- LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud Based Deep NetworksHang Zhou, Dongdong Chen, Jing Liao, Kejiang Chen et al.CVPR 2020
- Stabilized Medical Image AttacksGege Qi, Lijun Gong, Yibing Song, Kai Ma et al.ICLR 2021 · 34 citations
- GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative ModelsDingfan Chen, Ning Yu, Yang Zhang, Mario FritzCCS 2020 · 278 citations
- Augmenting Colonoscopy Using Extended and Directional CycleGAN for Lossy Image TranslationShawn Mathew, Saad Nadeem, Sruti Kumari, Arie E. KaufmanCVPR 2020
