arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

TwinGuard-Lite:面向生成式患者数字孪生的基于规则的状态准入网关

TwinGuard-Lite: A Rule-Based State-Admission Gateway for Generative Patient Digital Twins

Wenhui Chu, Sheikh Rabiul Islam

arXiv 2610.09012首次发表:更新:

发表机构

University at Albany, State University of New York(纽约州立大学奥尔巴尼分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

提出基于规则的TwinGuard-Lite网关,通过来源、矛盾和命名空间检查近似验证状态一致性与跨患者非干扰性,在eICU数据上实现99.1%精确率和90.5%召回率,证明无需语言模型即可实现机制级防护。

AI 中文摘要

未来的生成式患者数字孪生可能将纵向健康记录与语言模型智能体相结合,并在多次会话之间保留信息。一项拟议更新的措辞无法揭示其是否来自允许的来源、是否与患者记录冲突,或是否属于他人。我们提出了TwinGuard-Lite,一个基于规则的网关,仅当更新通过两个完整性属性的可检查近似时,才允许其进入孪生的持久状态。基于来源的状态一致性(GSC)通过来源检查和矛盾检查来近似;跨患者非干扰性(CPN)通过针对可信传输元数据的命名空间检查来近似。我们在基于公开许可的eICU数据库演示构建的半合成流的20个种子级患者划分上评估了三个攻击家族,每个种子有29,131±2,706个候选更新。关键词过滤器和异常检测器分别检测出16%和24%的攻击;仅来源的消融检测出59.9%的攻击,但漏掉了所有跨患者攻击。结合GSC和CPN可达到99.1%的精确率、90.5%的召回率、94.6%的F1分数和0.033%的假阳性率。完整网关接纳的每次攻击都虚假地声称来自可信来源;当检索通道这样做时,92.9%的检索攻击被接纳。结果在所述信任假设下成立,且未执行任何语言模型、智能体或检索器:TwinGuard-Lite是一个机制级概念验证,旨在推动经认证的、患者绑定的数据摄取,而非临床安全措施。

英文摘要

Future generative patient digital twins may combine longitudinal health records with language-model agents and keep information across sessions. The wording of a proposed update does not reveal whether it comes from an allowed source, conflicts with the patient's record, or belongs to someone else. We present TwinGuard-Lite, a rule-based gateway that admits an update to a twin's persistent state only if it passes checkable approximations of two integrity properties. Grounded state consistency (GSC) is approximated by a provenance check and a contradiction check; cross-patient noninterference (CPN) is approximated by a namespace check against trusted transport metadata. We evaluate three attack families over 20 seeded person-level splits of a semi-synthetic stream built from the openly licensed eICU database demo, with 29,131 $\pm$ 2706 candidate updates per seed. A keyword filter and an anomaly detector detect 16% and 24% of attacks, respectively; a provenance-only ablation detects 59.9% but misses every cross-patient attack. Combining GSC and CPN yields 99.1% precision, 90.5% recall, a 94.6% F1 score, and a 0.033% false-positive rate. Every attack the full gateway admits falsely claims a trusted source; when the retrieval channel does so, 92.9% of retrieval attacks are admitted. The results hold under stated trust assumptions, and no language model, agent, or retriever is executed: TwinGuard-Lite is a mechanism-level proof of concept that motivates authenticated, patient-bound ingestion, not a clinical safeguard.

Comments6 pages, 2 figures, 1 table. Accepted to HealthSec'26 (Cybersecurity in Healthcare), co-located with ACSAC 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑