Search papers, labs, and topics across Lattice.
This study introduces ConformalShift, a novel bounded event-reordering attack that effectively suppresses the detection of clinically significant ventricular heartbeat classes in adaptive ECG monitoring systems. By manipulating the order of authentic preceding events, the method significantly increases the failure rate of classifiers, achieving suppression rates of 66.7% and 60.0% for Extra Trees and HistGradientBoosting, respectively, compared to much lower rates with random scheduling. These findings highlight a critical vulnerability in adaptive monitoring systems, demonstrating that timing manipulation of genuine data can compromise patient safety without altering the data itself.
Event timing can be weaponized to bypass ECG monitoring systems, achieving up to 66.7% suppression of critical heartbeat classifications without altering the data itself.
Adaptive conformal prediction can recover clinically important heartbeat classes missed by a point classifier, but delayed feedback makes its decisions sensitive to event order. We introduce ConformalShift, a bounded event-reordering attack that suppresses the ventricular class for rescued events without modifying ECG waveforms, labels, classifier scores, or the event multiset. ConformalShift searches for feasible permutations of authentic preceding events that lower the ventricular threshold before a selected target is evaluated. On disjoint MIT--BIH confirmation records, the attack suppressed 66.7% of eligible targets for Extra Trees and 60.0% for HistGradientBoosting, compared with random-schedule rates of 4.4% and 12.0%, respectively. Transferred configurations also outperformed random scheduling on INCART, while reducing the displacement budget weakened the attack on both datasets. These results show that adaptive monitors in healthcare can be compromised through the timing of authentic information, even when waveforms, labels, classifier outputs, and event contents remain unchanged.