PhysioTRACE:面向生理基础模型的来源感知压力测试
PhysioTRACE: Provenance-Aware Stress Tests for Physiological Foundation Models
浏览论文内容
中文总结 AI 辅助
PhysioTRACE提出四轴行为审计,检测生理基础模型是否依赖采集来源捷径,并通过压力测试与干预认证,实现可验证的鲁棒性评估。
中文摘要 AI 辅助
生理基础模型在编码其反映的生理信号的同时,也编码了信号的记录方式。当记录条件与诊断相关时,这种采集来源可能成为一种捷径,然而常规的证据——迁移偏移和来源可解码性——并不能显示预测器是否使用了这一捷径。我们引入了PhysioTRACE,一种针对冻结编码器的四轴行为审计方法,它将探针可解码的内容与固定任务头所依赖的内容区分开来。恢复(Recover)评估来源的可解码程度;压力(Stress)仅在相同的保留记录上反转来源与目标之间的关联;干预(Intervene)移除一个训练局部化的来源成分;验证(Verify)仅在移除效果在声明的效用裕度内优于匹配的随机投影时才予以认证。因此,每次审计最终会得出三种结论之一:无依赖,或依赖且补救措施已认证或已拒绝。在脑电图(EEG)和心电图(ECG)上,跨越五种训练目标和五个冻结基础模型,恢复(Recover)的校准分数与分布外效用之间的关系在不同数据集间符号发生变化,因此两者都不能替代依赖测试。在成对的脑电图(EEG)视图上,由于捷径是通过构造已知的,审计检测到了它(当关联反转时,暴露的头损失约0.2 AUROC,而对照组头不受影响),并认证了移除一个秩二成分,该成分恢复了对照组水平的行为,且没有可测量的效用损失,对两种测试的编码器目标均如此。在真实的心电图(ECG)设备元数据上,它返回了所有三种结论:它认证了一种补救措施,消除了一个模型91%的额外脆弱性;在设备与诊断几乎不相关的情况下未发现依赖;并拒绝了对第二个模型的补救措施,因为其局部化方向也携带任务信号。因此,对输入记录方式的鲁棒性需要一种行为测试,而PhysioTRACE提供了一种可以通过、失败或拒绝补救措施的测试。
英文摘要
Physiological foundation models encode how a signal was recorded alongside the physiology it reflects. When recording conditions are associated with diagnosis, this acquisition provenance can become a shortcut, yet the usual evidence, shifted transfer and provenance decodability, does not show whether a predictor uses it. We introduce PhysioTRACE, a four-axis behavioral audit for frozen encoders that separates what a probe can decode from what a fixed task head relies on. Recover scores how decodable provenance is; Stress reverses only the provenance-target association on the same held-out records; Intervene removes a train-localized provenance component; and Verify certifies that removal only if it beats matched random projections within a declared utility margin. Each audit thus ends in one of three verdicts: no reliance, or reliance with the remedy certified or refused. Across EEG and ECG, five training objectives, and five frozen foundation models, the relation between Recover's calibrated score and out-of-distribution utility changes sign between datasets, so neither can stand in for a reliance test. On paired EEG views where the shortcut is known by construction, the audit detects it (the exposed head loses about 0.2 AUROC when the association is reversed, while a control head is unaffected) and certifies removal of a rank-two component that restores control-level behavior without measurable utility loss, for both encoder objectives tested. On real ECG device metadata it returns all three verdicts: it certifies a remedy that removes 91% of one model's excess vulnerability, finds no reliance where device and diagnosis are barely associated, and refuses the remedy for a second model whose localized direction also carries task signal. Robustness to how inputs were recorded therefore needs a behavioral test, and PhysioTRACE provides one that can pass, fail, or refuse a remedy.
发表机构
- Mohamed bin Zayed University of Artificial Intelligence (MBZUAI)(穆罕默德·本·扎耶德人工智能大学)
- McGill University(麦吉尔大学)
- Carnegie Mellon University(卡内基梅隆大学)
机构由 AI 辅助整理,请以论文原文为准。