Adversarial Beats: Feasibility Study of Spoofed Arrhythmia in Automated Electrocardiogram Diagnosis
Taiga Ono, Takeshi Sugawara, Jun Sakuma, Tatsuya Mori · ACM Transactions on Cyber-Physical Systems · 2025
This study aims to assess the feasibility of applying adversarial examples to attack cardiac diagnosis systems powered by machine learning algorithms. To achieve this, we introduce “ adversarial beats ,” which are adversarial perturbations that are tailored specifically against classification systems designed to diagnose electrocardiograms (ECGs). We first formulated an algorithm to generate adversarial examples for multiple neural network models for ECG classification and studied their attack success rates. Next, to evaluate their feasibility in a physical environment, we mounted a hardware attack by designing a malicious signal generator that injects adversarial beats into ECG sensor readings using commercial off-the-shelf hardware. To the best of our knowledge, our research is the first to evaluate the proficiency of adversarial examples for ECGs in a physical setup. Our real-world experiments demonstrate that, against an automated ECG diagnosis apparatus, our attack method can fake the presence of potential signs of cardiomyopathy with approximately 42.1% chance of success and the attacker can repeat the attack until a fraudulent insurance claim or other health care fraud is established. Based on the comprehensive feasibility study of attacks using adversarial beats, we conclude that the attacks have a sufficient chance to succeed such that an attacker may be incentivized to fake the presence of cardiomyopathy, potentially leading to unnecessary medication prescriptions and fraudulent medical insurance claims.