Machine Learning with Electronic Health Records is vulnerable to Backdoor Trigger Attacks

Electronic Health Records (EHRs) provide a wealth of information for machine\nlearning algorithms to predict the patient outcome from the data including\ndiagnostic information, vital signals, lab tests, drug administration, and\ndemographic information. Machine learning models can be built, for example, to\nevaluate patients based on their predicted mortality or morbidity and to\npredict required resources for efficient resource management in hospitals. In\nthis paper, we demonstrate that an attacker can manipulate the machine learning\npredictions with EHRs easily and selectively at test time by backdoor attacks\nwith the poisoned training data. Furthermore, the poison we create has\nstatistically similar features to the original data making it hard to detect,\nand can also attack multiple machine learning models without any knowledge of\nthe models. With less than 5% of the raw EHR data poisoned, we achieve average\nattack success rates of 97% on mortality prediction tasks with MIMIC-III\ndatabase against Logistic Regression, Multilayer Perceptron, and Long\nShort-term Memory models simultaneously.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC