[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-116903-en":3,"doc-seo-116903-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},116903,549758146520,"Patrick","https://ap-avatar.wpscdn.com/avatar/80002397d8c0411e94?_k=1775819394049821470",8,"Research & Report","Gradient-based enhancement attacks in biomedical machine learning - Research","Machine learning in biomedical research grows rapidly, yet the trustworthiness of reported results is frequently underestimated. This work studies “enhancement attacks,” which can falsely raise model performance while applying minimal changes to input features. Two gradient-based techniques are introduced: one enhances prediction performance broadly, and another enhances a specific method over a competing method. Experiments show classifiers can be falsely improved from 50% to near 100% with very high feature similarity (Pearson’s r′ s > 0.99).","arXiv :2301 .01885v2 [ stat .ML] 16 Aug 2023  \nGradient-based enhancement attacks in biomedical machine learning  \nMatthew Rosenblatt 1 , Javid Dadashkarimi2 , and Dustin Scheinost 1 ,3  \n1 Department of Biomedical Engineering, Yale University  \n2 Department of Computer Science, Yale University  \n3 Department of Radiology and Biomedical Imaging, Yale School of Medicine {matthew.rosenblatt,javid.dadashkarimi,[dustin.scheinost](dustin.scheinost}@yale.edu)[}](dustin.scheinost}@yale.edu)[@yale.edu](dustin.scheinost}@yale.edu)  \n[Abstract.](Abstract. The prevalence of machine learning in biomedical research is)[ The prevalence of machine learning in biomedical research is](Abstract. The prevalence of machine learning in biomedical research is)[ ](Abstract. The prevalence of machine learning in biomedical research is)rapidly growing, yet the trustworthiness of such research is often overlooked. While some previous works have investigated the ability of adversarial attacks to degrade model performance in medical imaging, the ability to falsely improve performance via recently-developed “enhancement attacks” may be a greater threat to biomedical machine learning. In the spirit of developing attacks to better understand trustworthiness, we developed two techniques to drastically enhance prediction performance of classifiers with minimal changes to features: 1) general enhancement of prediction performance, and 2) enhancement of a particular method over another. Our enhancement framework falsely improved classifiers’accuracy from 50% to almost 100% while maintaining high feature similarities between original and enhanced data (Pearson’s r′ s > 0.99) .  \nSimilarly, the method-specific enhancement framework was effective in falsely improving the performance of one method over another. For example, a simple neural network outperformed logistic regression by 17% on our enhanced dataset, although no performance differences were present in the original dataset. Crucially, the original and enhanced data were still similar (r = 0 .99) . Our results demonstrate the feasibility of minor data manipulations to achieve any desired prediction performance, which presents an interesting ethical challenge for the future of biomedical machine learning. These findings emphasize the need for more robust data provenance tracking and other precautionary measures to ensure the integrity of biomedical machine learning research. Code is available at [https://github.com/mattrosenblatt7/enhancement_EPIMI](https://github.com/mattrosenblatt7/enhancement_EPIMI).  \nKeywords: machine learning · adversarial attacks · neuroimaging  \n1 Introduction  \nMachine learning has demonstrated great success across numerous fields. However, the success of these models is not immune to attacks. Adversarial attacks, or data manipulations designed to alter the prediction [3], threaten realworld machine learning applications. Adversarial attacks include evasion attacks [2,30,12,4], where only test data are manipulated, or poisoning attacks [19,3,4,7],  \n2 Rosenblatt et al.  \nFig. 1. Overview of enhancement methods used in this paper. Classification accuracy in the original dataset is 50% . After applying gradient-based enhancement attacks following Algorithm 1, classification accuracy in the enhanced dataset is 99% . Using method enhancement attacks (Algorithm 2), datasets are altered such that a specific method (e.g., feedforward neural network) outperforms another (e.g., support vector machine) . In all cases, the changes between the original and enhanced datasets are minor. The “Downstream effects” box highlights possible implications of enhancement attacks.  \nwhere the attacker may contribute manipulated test and/or training data. Understanding adversarial attacks and developing corresponding defenses is crucial to the integrity of machine learning applications.  \nMachine learning is becoming increasingly prevalent in biomedical research—including biomedical imaging. Previous studi","cbCait3t68RAK8aP","https://ap.wps.com/l/cbCait3t68RAK8aP","pdf",3324531,1,12,"English","en",105,"# Introduction\n## Adversarial attacks in machine learning\n## Enhancement attacks as an ethical risk\n# Methods Overview\n## Gradient-based general enhancement\n## Method-specific enhancement\n## Downstream effects","[{\"question\":\"What problem do enhancement attacks address in biomedical machine learning?\",\"answer\":\"Enhancement attacks address the risk that models can be made to look more accurate through subtle data manipulations, undermining the trustworthiness of biomedical research results.\"},{\"question\":\"How do the two proposed enhancement techniques differ?\",\"answer\":\"One technique generally enhances prediction performance, while the second enhances one method over another by altering datasets so the target method outperforms the competitor.\"},{\"question\":\"What evidence does the work provide that enhanced data remain similar to original data?\",\"answer\":\"The study reports high feature similarity between original and enhanced datasets, including Pearson correlations around r ≈ 0.99, even when accuracy is dramatically improved.\"}]","Gradient-based enhancement attacks in biomedical machine learning - Research | PDF",1785672376,30,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"gradient-based-enhancement-attacks-in-biomedical-machine-learning-research","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/gradient-based-enhancement-attacks-in-biomedical-machine-learning-research/116903/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem do enhancement attacks address in biomedical machine learning?","Question",{"text":75,"@type":76},"Enhancement attacks address the risk that models can be made to look more accurate through subtle data manipulations, undermining the trustworthiness of biomedical research results.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How do the two proposed enhancement techniques differ?",{"text":80,"@type":76},"One technique generally enhances prediction performance, while the second enhances one method over another by altering datasets so the target method outperforms the competitor.",{"name":82,"@type":73,"acceptedAnswer":83},"What evidence does the work provide that enhanced data remain similar to original data?",{"text":84,"@type":76},"The study reports high feature similarity between original and enhanced datasets, including Pearson correlations around r ≈ 0.99, even when accuracy is dramatically improved.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":29,"slug":121},"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]