CT-GAN: Malicious Tampering of 3D Medical Imagery using Deep Learning

  • 2019-01-11 14:41:31
  • Yisroel Mirsky, Tom Mahler, Ilan Shelef, Yuval Elovici
  • 66

Abstract

In 2018, clinics and hospitals were hit with numerous attacks leading tosignificant data breaches and interruptions in medical services. An attackerwith access to medical records can do much more than hold the data for ransomor sell it on the black market. In this paper, we show how an attacker can usedeep learning to add or remove evidence of medical conditions from volumetric(3D) medical scans. An attacker may perform this act in order to stop apolitical candidate, sabotage research, commit insurance fraud, perform an actof terrorism, or even commit murder. We implement the attack using a 3Dconditional GAN and show how the framework (CT-GAN) can be automated. Althoughthe body is complex and 3D medical scans are very large, CT-GAN achievesrealistic results and can be executed in milliseconds. To evaluate the attack,we focus on injecting and removing lung cancer from CT scans. We show how threeexpert radiologists and a state-of-the-art deep learning AI could notdifferentiate between tampered and non-tampered scans. We also evaluatestate-of-the-art countermeasures and propose our own. Finally, we discuss thepossible attack vectors on modern radiology networks and demonstrate one of theattack vectors on an active CT scanner.

 

Quick Read (beta)

loading the full paper ...