100 fake samples are enough to use artificial intelligence to sabotage medical diagnoses

You don’t need to be a computer genius to sabotage an AI health support system. It would be enough for someone to enter 100 to 500 processed images into a database of millions.

This small amount of “digital poison” can be one hundred thousandth of the training data. With this small part, an artificial intelligence system designed to read X-rays or prescribe transplants can learn to fail. And it will not be done by chance. It can do this for a specific group of people while working with perfect accuracy for the rest of the population.

What is most alarming is not the ease of attack, but our current blindness. These tampers are statistically invisible to standard quality control. If these anomalies are discovered, the damage will have already been done.

The myth of safety in numbers

There is a common belief that the volume of data needed to power AI is itself a shield. We tend to think that in an ocean of millions of medical data, a few drops of false information dissolve harmlessly. The evidence strongly refutes this assumption.

Two research groups from the Karolinska Institute (SMAILE) in Sweden and from the Polytechnic University of Madrid (InnoTep) evaluated 41 key studies on the safety of medical artificial intelligence published in recent years. After this process, it can be concluded that the success of the attack does not depend on the percentage of corrupted data, but on the absolute number of samples.

This means that we are witnessing a structural vulnerability: AI systems are inherently susceptible to brief, disciplined and targeted manipulation.

Mechanics of multiple lies

How can a small amount of data fool such a complex system? The attack mechanism repeats the old maxim of authoritarian propaganda: “a lie repeated a thousand times becomes the truth.”

In machine learning, there is a phenomenon of indoctrination. That is, the system sees the data not once, but reviews them in repeated cycles. If you insert a shortened set of false samples, the system will process them again and again in these loops. In this way, these malicious patterns multiply their impact on the final result.

At this point, we have a system that has internalized a false reality. The worst thing is that “poisoned” artificial intelligence works fine for the largest number of patients: it “wrongs” only in cases and circumstances designed to fail.

The result of the attack is not a failed model, but a corrupted model. It keeps its overall utility intact, but does a selective purge against a target group, for example. This is not a random error; It is a mathematically coded discrimination disguised under the general appearance of efficiency.

The privacy paradox

Perhaps the most ironic conclusion of our work is that there are laws designed to protect us that highlight this danger. Basic rules such as the General Data Protection Regulation are important for ensuring patient privacy, but they can also inadvertently act as a shield for attackers.

To detect such subtle sabotage as the one explained, it would be necessary to cross-reference information from thousands of patients between different medical centers. However, the law limits exactly this kind of mass tracking and correlation of data.

This creates a “security paradox”. We protect patient privacy by blindfolding the system that is supposed to protect it. As a result, these attacks can remain hidden for a long time.

Defense based on plurality

In this context, traditional cyber security is not enough. In our research, we propose a defensive solution called MEDLEY (Medical Comprehensive Diagnostic System Using Diversity) for healthcare. Faced with the unique thinking of an optimized model, we offer the value of disagreement.

Our proposal is to create “digital medical dashboards” composed of different artificial intelligence systems, including our own previous versions, as well as different designs and manufacturers. With such a variety, an attacker could maliciously root one of them, but it would be very difficult to repeat the process for the others.

The consultation process will be through these ‘digital medical boards’. Of course, given the variety of AI systems involved, the results can be radically different. But when this happens, one should not impose a false unanimity. Instead, we should assume that there is no consensus and submit a caveat for human review.

The era of technological innocence regarding AI is over. We must not accept “black boxes” that absorb imposed truth. If we want machine learning to be a positive element in our healthcare, it is essential to understand its limitations and correct them with the rigor of our procedures and human knowledge.

Leave a Reply

Your email address will not be published. Required fields are marked *