通过神经网络权重替换实现高容量鲁棒医学图像窃取
High-Capacity Robust Medical Image Exfiltration via Neural Network Weight Replacement
- Université Côte d'Azur(蔚蓝海岸大学)
- Inria(法国国家信息与自动化研究所)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文提出一种高容量神经隐写攻击,通过将医学图像编码为连续潜在表示嵌入模型权重,实现鲁棒且可扩展的数据窃取,并揭示现有参数级防御的不足。
AI中文摘要:
协作式医学AI平台允许研究人员在限制数据导出的同时,在敏感影像数据上训练模型。然而,训练后的模型可作为患者信息的隐蔽载体:医学图像可被编码进模型参数中,并在安全环境之外重建。现有防御措施依赖于轻量级净化(如微调、剪枝、量化)和有限的统计审计,从而造成了现实中的内部人员窃取风险。我们提出了一种高容量神经隐写攻击,将医学图像编码为连续潜在表示,并嵌入到模型初始化中。基于StyleGAN2的对抗自编码器学习紧凑的潜在编码,并正则化以匹配标准权重初始化统计特性,使嵌入参数与干净模型在统计上保持一致。训练期间注入噪声可增强对导出时缓解措施的鲁棒性。载体模型在其预期任务上保持功能正常,隐藏图像可在导出后直接从其权重中重建。这种连续编码实现了鲁棒且可扩展的窃取,允许在30MB模型中嵌入多达99个脑部MRI体积,并在破坏先前比特级方案的缓解措施下仍可恢复。虽然重建是近似而非像素精确的,但嵌入内容在解剖学上仍可识别,并可大规模恢复,这暴露了与先前比特级方法不同的隐私风险。在MIMIC-CXR、BraTS和LiTS上的实验证明了跨模态、任务和架构的有效性,凸显了对超越参数级净化的结构性防御的需求。代码可在该https URL获取。
英文摘要:
Collaborative medical AI platforms allow researchers to train models on sensitive imaging data while restricting data export. However, trained models can serve as covert carriers of patient information: medical images may be encoded within model parameters and reconstructed outside the secure environment. Existing defenses rely on lightweight sanitization (e.g., fine-tuning, pruning, quantization) and limited statistical auditing, creating a realistic insider exfiltration risk. We introduce a high-capacity neural steganography attack that encodes medical images as continuous latent representations embedded into model initialization. A StyleGAN2-based adversarial autoencoder learns compact latent codes regularized to match standard weight initialization statistics, keeping embedded parameters statistically consistent with clean models. Noise injection during training improves robustness to export-time mitigation. The carrier model remains functional on its intended task and hidden images can be reconstructed directly from its weights after export. This continuous encoding enables robust and scalable exfiltration, allowing up to 99 brain MRI volumes to be embedded within a 30MB model, and remains recoverable under mitigations that disrupt prior bit-level schemes. While reconstructions are approximate rather than pixel-exact, embedded content remains anatomically recognizable and recoverable at scale, exposing a privacy risk distinct from prior bit-level approaches. Experiments on MIMIC-CXR, BraTS, and LiTS demonstrate effectiveness across modalities, tasks, and architectures, highlighting the need for structural defenses beyond parameter-level sanitization. Code is available at https://github.com/ElieThellier/high-capacity-robust-medical-image-exfiltration.