Medical Multimodal Model Stealing Attacks via Adversarial Domain Alignment

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Shen, Yaling, Zhuang, Zhixiong, Yuan, Kun, Nicolae, Maria-Irina, Navab, Nassir, Padoy, Nicolas, Fritz, Mario
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866912219621490688
author Shen, Yaling
Zhuang, Zhixiong
Yuan, Kun
Nicolae, Maria-Irina
Navab, Nassir
Padoy, Nicolas
Fritz, Mario
author_facet Shen, Yaling
Zhuang, Zhixiong
Yuan, Kun
Nicolae, Maria-Irina
Navab, Nassir
Padoy, Nicolas
Fritz, Mario
contents Medical multimodal large language models (MLLMs) are becoming an instrumental part of healthcare systems, assisting medical personnel with decision making and results analysis. Models for radiology report generation are able to interpret medical imagery, thus reducing the workload of radiologists. As medical data is scarce and protected by privacy regulations, medical MLLMs represent valuable intellectual property. However, these assets are potentially vulnerable to model stealing, where attackers aim to replicate their functionality via black-box access. So far, model stealing for the medical domain has focused on classification; however, existing attacks are not effective against MLLMs. In this paper, we introduce Adversarial Domain Alignment (ADA-STEAL), the first stealing attack against medical MLLMs. ADA-STEAL relies on natural images, which are public and widely available, as opposed to their medical counterparts. We show that data augmentation with adversarial noise is sufficient to overcome the data distribution gap between natural images and the domain-specific distribution of the victim MLLM. Experiments on the IU X-RAY and MIMIC-CXR radiology datasets demonstrate that Adversarial Domain Alignment enables attackers to steal the medical MLLM without any access to medical data.
format Preprint
id arxiv_https___arxiv_org_abs_2502_02438
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Medical Multimodal Model Stealing Attacks via Adversarial Domain Alignment
Shen, Yaling
Zhuang, Zhixiong
Yuan, Kun
Nicolae, Maria-Irina
Navab, Nassir
Padoy, Nicolas
Fritz, Mario
Cryptography and Security
Artificial Intelligence
Medical multimodal large language models (MLLMs) are becoming an instrumental part of healthcare systems, assisting medical personnel with decision making and results analysis. Models for radiology report generation are able to interpret medical imagery, thus reducing the workload of radiologists. As medical data is scarce and protected by privacy regulations, medical MLLMs represent valuable intellectual property. However, these assets are potentially vulnerable to model stealing, where attackers aim to replicate their functionality via black-box access. So far, model stealing for the medical domain has focused on classification; however, existing attacks are not effective against MLLMs. In this paper, we introduce Adversarial Domain Alignment (ADA-STEAL), the first stealing attack against medical MLLMs. ADA-STEAL relies on natural images, which are public and widely available, as opposed to their medical counterparts. We show that data augmentation with adversarial noise is sufficient to overcome the data distribution gap between natural images and the domain-specific distribution of the victim MLLM. Experiments on the IU X-RAY and MIMIC-CXR radiology datasets demonstrate that Adversarial Domain Alignment enables attackers to steal the medical MLLM without any access to medical data.
title Medical Multimodal Model Stealing Attacks via Adversarial Domain Alignment
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2502.02438