Deep learning models for electrocardiograms are susceptible to adversarial attack
- 9 March 2020
- journal article
- research article
- Published by Springer Science and Business Media LLC in Nature Medicine
- Vol. 26 (3), 360-363
- https://doi.org/10.1038/s41591-020-0791-x
Abstract
Electrocardiogram (ECG) acquisition is increasingly widespread in medical and commercial devices, necessitating the development of automated interpretation strategies. Recently, deep neural networks have been used to automatically analyze ECG tracings and outperform physicians in detecting certain rhythm irregularities1. However, deep learning classifiers are susceptible to adversarial examples, which are created from raw data to fool the classifier such that it assigns the example to the wrong class, but which are undetectable to the human eye2,3. Adversarial examples have also been created for medical-related tasks4,5. However, traditional attack methods to create adversarial examples do not extend directly to ECG signals, as such methods introduce square-wave artefacts that are not physiologically plausible. Here we develop a method to construct smoothed adversarial examples for ECG tracings that are invisible to human expert evaluation and show that a deep learning model for arrhythmia detection from single-lead ECG6 is vulnerable to this type of attack. Moreover, we provide a general technique for collating and perturbing known adversarial examples to create multiple new ones. The susceptibility of deep learning ECG algorithms to adversarial misclassification implies that care should be taken when evaluating these models on ECGs that may have been altered, particularly when incentives for causing misclassification exist.Keywords
Funding Information
- National Heart and Lung Institute (R01HL148248, R01HL148248)
This publication has 13 references indexed in Scilit:
- Adversarial attacks on medical machine learningScience, 2019
- Deep Neural Network Compression for Aircraft Collision Avoidance SystemsJournal of Guidance, Control, and Dynamics, 2019
- Cardiologist-level arrhythmia detection and classification in ambulatory electrocardiograms using a deep neural networkNature Medicine, 2019
- Deep Feature Learning for Sudden Cardiac Arrest Detection in Automated External DefibrillatorsScientific Reports, 2018
- Generalizability vs. Robustness: Investigating Medical Imaging Networks Using Adversarial ExamplesPublished by Springer Science and Business Media LLC ,2018
- AF Classification from a Short Single Lead ECG Recording: the Physionet Computing in Cardiology Challenge 2017Computing in Cardiology, 2017
- ENCASE: an ENsemble ClASsifiEr for ECG Classification Using Expert Features and Deep Neural NetworksPublished by Computing in Cardiology ,2017
- The Evolution of Ambulatory ECG MonitoringProgress in Cardiovascular Diseases, 2013
- A dynamical model for generating synthetic electrocardiogram signalsIEEE Transactions on Biomedical Engineering, 2003
- Gradient-based learning applied to document recognitionProceedings of the IEEE, 1998