Papers
Topics
Authors
Recent
Gemini 2.5 Flash
Gemini 2.5 Flash
41 tokens/sec
GPT-4o
59 tokens/sec
Gemini 2.5 Pro Pro
41 tokens/sec
o3 Pro
7 tokens/sec
GPT-4.1 Pro
50 tokens/sec
DeepSeek R1 via Azure Pro
28 tokens/sec
2000 character limit reached

Medical Foundation Models are Susceptible to Targeted Misinformation Attacks (2309.17007v1)

Published 29 Sep 2023 in cs.LG, cs.AI, and cs.CY

Abstract: LLMs have broad medical knowledge and can reason about medical information across many domains, holding promising potential for diverse medical applications in the near future. In this study, we demonstrate a concerning vulnerability of LLMs in medicine. Through targeted manipulation of just 1.1% of the model's weights, we can deliberately inject an incorrect biomedical fact. The erroneous information is then propagated in the model's output, whilst its performance on other biomedical tasks remains intact. We validate our findings in a set of 1,038 incorrect biomedical facts. This peculiar susceptibility raises serious security and trustworthiness concerns for the application of LLMs in healthcare settings. It accentuates the need for robust protective measures, thorough verification mechanisms, and stringent management of access to these models, ensuring their reliable and safe use in medical practice.

User Edit Pencil Streamline Icon: https://streamlinehq.com
Authors (12)
  1. Tianyu Han (20 papers)
  2. Sven Nebelung (23 papers)
  3. Firas Khader (17 papers)
  4. Tianci Wang (3 papers)
  5. Gustav Mueller-Franzes (5 papers)
  6. Christiane Kuhl (22 papers)
  7. Sebastian Försch (1 paper)
  8. Jens Kleesiek (80 papers)
  9. Christoph Haarburger (9 papers)
  10. Keno K. Bressem (13 papers)
  11. Jakob Nikolas Kather (34 papers)
  12. Daniel Truhn (51 papers)
Citations (6)