CT-GAN: Malicious Tampering of 3D Medical Imagery using Deep Learning
Yisroel Mirsky, Tom Mahler, Ilan Shelef, Yuval Elovici
摘要
In 2018, clinics and hospitals were hit with numerous attacks leading to significant data breaches and interruptions in medical services. An attacker with access to medical records can do much more than hold the data for ransom or sell it on the black market. In this paper, we show how an attacker can use deep-learning to add or remove evidence of medical conditions from volumetric (3D) medical scans. An attacker may perform this act in order to stop a political candidate, sabotage research, commit insurance fraud, perform an act of terrorism, or even commit murder. We implement the attack using a 3D conditional GAN and show how the framework (CT-GAN) can be automated. Although the body is complex and 3D medical scans are very large, CT-GAN achieves realistic results which can be executed in milliseconds. To evaluate the attack, we focused on injecting and removing lung cancer from CT scans. We show how three expert radiologists and a state-of-the-art deep learning AI are highly susceptible to the attack. We also explore the attack surface of a modern radiology network and demonstrate one attack vector: we intercepted and manipulated CT scans in an active hospital network with a covert penetration test. Demo video: this https URL Source code: this https URL
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition SystemsShangyu Xie, Han Wang, Yu Kong, Yuan HongS&P 2022 · 被引用 32 次
- Correction-based Defense Against Adversarial Video Attacks via Discretization-Enhanced Video Compressive SensingWei Song, Cong Cong, Haonan Zhong, Jingling XueUSENIX Security 2024 · 被引用 8 次
- Patching Up: Stakeholder Experiences of Security Updates for Connected Medical DevicesLorenz Kustosch, Carlos Gañán, Michel van Eeten, Simon ParkinUSENIX Security 2025
- Synthetic Learning: Learn From Distributed Asynchronized Discriminator GAN Without Sharing Medical Image DataQi Chang, Hui Qu, Yikai Zhang, Mert R. Sabuncu 等CVPR 2020
- XCheck: Verifying Integrity of 3D Printed Patient-Specific Devices via Computing TomographyZhiyuan Yu, Yuanhaur Chang, Shixuan Zhai, Nicholas Deily 等USENIX Security 2023
它引用的顶会 Paper1
相关 Paper
- ConfounderGAN: Protecting Image Data Privacy with Causal ConfounderQi Tian, Kun Kuang, Kelu Jiang, Furui Liu 等NeurIPS 2022 · 被引用 11 次
- LG-GAN: Label Guided Adversarial Network for Flexible Targeted Attack of Point Cloud Based Deep NetworksHang Zhou, Dongdong Chen, Jing Liao, Kejiang Chen 等CVPR 2020
- Stabilized Medical Image AttacksGege Qi, Lijun Gong, Yibing Song, Kai Ma 等ICLR 2021 · 被引用 34 次
- GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative ModelsDingfan Chen, Ning Yu, Yang Zhang, Mario FritzCCS 2020 · 被引用 278 次
- Augmenting Colonoscopy Using Extended and Directional CycleGAN for Lossy Image TranslationShawn Mathew, Saad Nadeem, Sruti Kumari, Arie E. KaufmanCVPR 2020
