Abstract
Although deep learning models trained on electronic health records (EHR) data have shown state-of-the-art performance in many predictive clinical tasks, the discovery of adversarial examples (i.e., input data that are engineered to cause misclassification) has exposed vulnerabilities with lab and imaging data. We specifically consider adversarial examples with longitudinal EHR data, an area that has not been previously examined because of the challenges with temporal high-dimensional and sparse features. We propose Longitudinal AdVersarial Attack (LAVA), a saliency score based adversarial example using a method that requires a minimal number of perturbations and that automatically minimizes the likelihood of detection. Features are selected and modified by jointly modeling a saliency map and attention mechanism. Experimental results with longitudinal EHR data show that LAVA can substantially reduce model performance for attention-based target models (from AUPR = 0.5 to AUPR = 0.08).
Author supplied keywords
Cite
CITATION STYLE
An, S., Stewart, W. F., Xiao, C., & Sun, J. (2019). Lava: Longitudinal adversarial attack on electronic health records data. In The Web Conference 2019 - Proceedings of the World Wide Web Conference, WWW 2019 (pp. 2558–2564). Association for Computing Machinery, Inc. https://doi.org/10.1145/3308558.3313528
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.