CohortHijack:单细胞注释对伴随细胞移除的鲁棒性
CohortHijack: Robustness of Single Cell Annotation to Companion Cell Removal
浏览论文内容
中文总结 AI 辅助
本研究提出CohortHijack鲁棒性审计方法,证实通过移除少量伴随细胞可操纵单细胞注释的修正标签,揭示查询队列组成是单细胞注释的攻击面。
中文摘要 AI 辅助
许多单细胞注释工具会利用邻近细胞或簇级投票来修正初始细胞标签。本研究探讨能否在不改变目标细胞的情况下操纵这种修正过程。我们提出CohortHijack,一种鲁棒性审计方法,该方法会从查询队列中移除选定的非目标细胞,同时保留目标细胞的表达谱、基础预测结果以及训练好的模型。我们在PBMC3K和Paul15数据集上,结合逻辑回归和校准线性SVM分类器,评估了随机移除、结构化移除方法,以及贪心、多起点和束搜索策略。在Paul15数据集上,结构化移除的效果始终强于随机移除。多起点搜索在移除小部分队列的情况下,使线性SVM分类器的目标细胞标签改变了24.33%,逻辑回归分类器的目标细胞标签改变了19.67%,同时平均附带变化低于0.4%。消融实验证实,当禁用邻域修正时,该效果会消失。我们还评估了CellTypist的多数投票机制,其独立预测结果在所有评估中保持不变,但修正后的标签在小部分伴随细胞被移除后发生了改变。这些发现表明,查询队列组成是单细胞注释中一种可保留目标细胞的攻击面。
英文摘要
Many single-cell annotation tools refine an initial cell label using nearby cells or cluster-level voting. We study whether this refinement can be manipulated without changing the target cell. We introduce CohortHijack, a robustness audit that removes selected non-target cells from the query cohort while preserving the target expression profile, base prediction, and trained model. We evaluate random and structured removal methods, together with greedy, multi-start, and beam search, on PBMC3K and Paul15 using logistic regression and calibrated linear SVM classifiers. Structured removal was consistently stronger than random removal on Paul15. Multi-start search changed 24.33% of linear-SVM targets and 19.67% of logistic-regression targets while removing a small fraction of the cohort and keeping mean collateral changes below 0.4%. Ablations confirmed that the effect disappeared when neighborhood refinement was disabled. We also evaluated CellTypist majority voting, where independent predictions remained unchanged across all evaluations, but refined labels changed after small companion-cell removals. These findings identify query cohort composition as a target-preserving attack surface in single-cell annotation.
发表机构
- Faculty of Computer Science, University of New Brunswick(新不伦瑞克大学计算机科学学院)
- Farzanegan Amin 2 High School(法尔扎内甘阿明第二高中)
机构由 AI 辅助整理,请以论文原文为准。