Related Experiment Video
Updated: Jan 24, 2026

Author Spotlight: Addressing Technical and Subjective Challenges in Measuring Classroom Attention
Published on: December 15, 2023
Data Poisoning Vulnerabilities Across Health Care Artificial Intelligence Architectures: Analytical Security
Farhad Abtahi1,2,3, Fernando Seoane1,4,5,3, Ivan Pau6
1Department of Clinical Science, Intervention and Technology, Karolinska Institutet, Huddinge, Stockholm, Sweden.
Health care AI is vulnerable to data-poisoning attacks, with few samples causing significant compromise. Current regulations hinder detection, necessitating a multilayered defense strategy for patient safety.
Area of Science:
- Medical Artificial Intelligence
- Cybersecurity in Healthcare
- AI Model Security
Background:
- Health care AI systems are increasingly integrated into clinical workflows but remain vulnerable to data-poisoning attacks.
- A small number of manipulated training samples can compromise AI models used for diagnosis, documentation, and resource allocation.
- Existing privacy regulations may inadvertently complicate anomaly detection and auditing, limiting visibility into adversarial activity.
Purpose of the Study:
- Provide a comprehensive threat analysis of data poisoning vulnerabilities across major health care AI architectures.
- Identify attack surfaces in clinical AI systems.
- Propose a multilayered defense framework suitable for health care settings.
Main Methods:
- Synthesized empirical findings from 41 security studies (2019-2025) into a health care-specific threat-modeling framework.
- Constructed 8 hypothetical attack scenarios across AI architectures, federated learning, clinical documentation, resource allocation, and supply chains.
- Aligned scenarios with realistic insider-access threat models and current clinical deployment practices.
Main Results:
- Attackers with as few as 100-500 poisoned samples can compromise health care AI systems (≥60% success rate).
- Attack success depends on the absolute number of poisoned samples, challenging assumptions about large datasets providing inherent protection.
- Detection delays range from 6-12 months, potentially years in distributed or privacy-constrained environments; privacy regulations further complicate detection.
Conclusions:
- Health care AI systems face significant security challenges inadequately addressed by current regulations and validation practices.
- A multilayered defense strategy is proposed, combining ensemble disagreement monitoring, adversarial testing, privacy-preserving auditable mechanisms, and strengthened governance.
- Ensuring patient safety may require a shift towards more interpretable and verifiable AI architectures over opaque, high-performance models.
Related Concept Videos
Interdisciplinary Care: The Health Care Team-I
Physicians
The physician's primary responsibility is to diagnose illness and direct the medical or surgical treatment of the condition. The authority to admit patients to a healthcare agency or institution and practice care within that setting is granted to physicians by the healthcare agency or institution...
Interdisciplinary Care: The Health Care Team-II
Physical Therapist
A physical therapist (PT) aims to restore function or prevent additional impairment in a patient following an injury or disease. Massage, heat, cold, water, sonar waves, exercises, and electrical stimulation are some treatments used by PTs to treat...
Traditional Level Of Health Care System
The preventive healthcare service includes tests for screening. Preventive health care services include identifying and reducing disease risk...
Introduction To Health Care Delivery System
The Institute of Medicine (IOM) advocates for a patient-centered, effective, safe, timely, equitable, and effective healthcare system. The National Priorities...
Enhanced Elimination of Poison
Antidotes serve a crucial role in counteracting the effects of poison by inhibiting enzymes responsible for producing harmful drug metabolites. In some cases, these toxic metabolites can be neutralized by endogenous cosubstrates, which are maintained at specific concentrations to prevent interaction with cellular macromolecules and subsequent cell death.
Renal excretion is the...
Prevention of Further Absorption of Poison

