{"id":"https://openalex.org/W4415191133","doi":"https://doi.org/10.48550/arxiv.2508.05677","title":"Adversarial Attacks on Reinforcement Learning-based Medical Questionnaire Systems: Input-level Perturbation Strategies and Medical Constraint Validation","display_name":"Adversarial Attacks on Reinforcement Learning-based Medical Questionnaire Systems: Input-level Perturbation Strategies and Medical Constraint Validation","publication_year":2025,"publication_date":"2025-08-05","ids":{"openalex":"https://openalex.org/W4415191133","doi":"https://doi.org/10.48550/arxiv.2508.05677"},"language":"en","primary_location":{"id":"pmh:oai:arXiv.org:2508.05677","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2508.05677","pdf_url":"https://arxiv.org/pdf/2508.05677","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"type":"preprint","indexed_in":["arxiv","datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2508.05677","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5030745240","display_name":"Peizhuo Liu","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Liu, Peizhuo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":0,"corresponding_author_ids":["https://openalex.org/A5030745240"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7143999934196472,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7143999934196472,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T13283","display_name":"Mental Health Research Topics","score":0.6496999859809875,"subfield":{"id":"https://openalex.org/subfields/3205","display_name":"Experimental and Cognitive Psychology"},"field":{"id":"https://openalex.org/fields/32","display_name":"Psychology"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.8906000256538391},{"id":"https://openalex.org/keywords/markov-decision-process","display_name":"Markov decision process","score":0.6212000250816345},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.5073999762535095},{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.42669999599456787},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.37790000438690186},{"id":"https://openalex.org/keywords/medical-practice","display_name":"Medical practice","score":0.35679998993873596},{"id":"https://openalex.org/keywords/gradient-descent","display_name":"Gradient descent","score":0.35569998621940613},{"id":"https://openalex.org/keywords/markov-process","display_name":"Markov process","score":0.34779998660087585}],"concepts":[{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.8906000256538391},{"id":"https://openalex.org/C106189395","wikidata":"https://www.wikidata.org/wiki/Q176789","display_name":"Markov decision process","level":3,"score":0.6212000250816345},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6007000207901001},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.5073999762535095},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4447999894618988},{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.42669999599456787},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3955000042915344},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.37790000438690186},{"id":"https://openalex.org/C2993312423","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medical practice","level":2,"score":0.35679998993873596},{"id":"https://openalex.org/C153258448","wikidata":"https://www.wikidata.org/wiki/Q1199743","display_name":"Gradient descent","level":3,"score":0.35569998621940613},{"id":"https://openalex.org/C159886148","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov process","level":2,"score":0.34779998660087585},{"id":"https://openalex.org/C2776036281","wikidata":"https://www.wikidata.org/wiki/Q48769818","display_name":"Constraint (computer-aided design)","level":2,"score":0.3393999934196472},{"id":"https://openalex.org/C534262118","wikidata":"https://www.wikidata.org/wiki/Q177719","display_name":"Medical diagnosis","level":2,"score":0.31189998984336853},{"id":"https://openalex.org/C143587482","wikidata":"https://www.wikidata.org/wiki/Q1543216","display_name":"Iterative and incremental development","level":2,"score":0.30630001425743103},{"id":"https://openalex.org/C45374587","wikidata":"https://www.wikidata.org/wiki/Q12525525","display_name":"Computation","level":2,"score":0.30169999599456787},{"id":"https://openalex.org/C177918212","wikidata":"https://www.wikidata.org/wiki/Q803623","display_name":"Perturbation (astronomy)","level":2,"score":0.29499998688697815},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.289000004529953},{"id":"https://openalex.org/C98763669","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov chain","level":2,"score":0.27079999446868896},{"id":"https://openalex.org/C42475967","wikidata":"https://www.wikidata.org/wiki/Q194292","display_name":"Operations research","level":1,"score":0.2648000121116638},{"id":"https://openalex.org/C106977388","wikidata":"https://www.wikidata.org/wiki/Q2752427","display_name":"Medical research","level":2,"score":0.2632000148296356},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.25870001316070557},{"id":"https://openalex.org/C2983241795","wikidata":"https://www.wikidata.org/wiki/Q6806500","display_name":"Medical decision making","level":2,"score":0.2508000135421753}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:oai:arXiv.org:2508.05677","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2508.05677","pdf_url":"https://arxiv.org/pdf/2508.05677","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},{"id":"doi:10.48550/arxiv.2508.05677","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2508.05677","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"Preprint"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2508.05677","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2508.05677","pdf_url":"https://arxiv.org/pdf/2508.05677","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"RL-based":[0,221],"medical":[1,9,119,125,134,215,222],"questionnaire":[2,223],"systems":[3,224],"have":[4],"shown":[5],"great":[6],"potential":[7,33],"in":[8,142,182],"scenarios.":[10],"However,":[11],"their":[12,32],"safety":[13],"and":[14,30,53,56,99,132],"robustness":[15],"remain":[16,112],"unresolved.":[17],"This":[18],"study":[19],"performs":[20],"a":[21,41,63,68,117,138],"comprehensive":[22,118],"evaluation":[23],"on":[24,152,177,217],"adversarial":[25,110,146,188],"attack":[26,75,197],"methods":[27],"to":[28,61,66,166,204],"identify":[29],"analyze":[31],"vulnerabilities.":[34,228],"We":[35,70,136,148,173],"formulate":[36],"the":[37,47,50,57,78,108,153,168,178,193,218],"diagnosis":[38],"process":[39],"as":[40],"Markov":[42],"Decision":[43],"Process":[44],"(MDP),":[45],"where":[46],"state":[48],"is":[49,59],"patient":[51],"responses":[52],"unasked":[54],"questions,":[55],"action":[58],"either":[60],"ask":[62],"question":[64],"or":[65],"make":[67],"diagnosis.":[69],"implemented":[71],"six":[72],"prevailing":[73],"major":[74],"methods,":[76],"including":[77,127],"Fast":[79],"Gradient":[80,85],"Signed":[81],"Method":[82,96],"(FGSM),":[83],"Projected":[84],"Descent":[86],"(PGD),":[87],"Carlini":[88],"&amp;":[89],"Wagner":[90],"Attack":[91],"(C&amp;W)":[92],"attack,":[93],"Basic":[94],"Iterative":[95],"(BIM),":[97],"DeepFool,":[98],"AutoAttack,":[100],"with":[101,196],"seven":[102],"epsilon":[103],"values":[104],"each.":[105],"To":[106],"ensure":[107],"generated":[109],"examples":[111],"clinically":[113,144],"plausible,":[114],"we":[115],"developed":[116],"validation":[120],"framework":[121,180],"consisting":[122],"of":[123,163],"247":[124],"constraints,":[126],"physiological":[128],"bounds,":[129],"symptom":[130],"correlations,":[131],"conditional":[133],"constraints.":[135],"achieved":[137],"97.6%":[139],"success":[140,198],"rate":[141],"generating":[143],"plausible":[145],"samples.":[147],"performed":[149],"our":[150,175],"experiment":[151],"National":[154],"Health":[155],"Interview":[156],"Survey":[157],"(NHIS)":[158],"dataset":[159],"(https://www.cdc.gov/nchs/nhis/),":[160],"which":[161],"consists":[162],"182,630":[164],"samples,":[165],"predict":[167],"participant's":[169],"4-year":[170],"mortality":[171],"rate.":[172],"evaluated":[174],"attacks":[176,189],"AdaptiveFS":[179],"proposed":[181],"arXiv:2004.00994.":[183],"Our":[184,207],"results":[185],"show":[186,226],"that":[187,211],"could":[190],"significantly":[191],"impact":[192],"diagnostic":[194],"accuracy,":[195],"rates":[199],"ranging":[200],"from":[201],"33.08%":[202],"(FGSM)":[203],"64.70%":[205],"(AutoAttack).":[206],"work":[208],"has":[209],"demonstrated":[210],"even":[212],"under":[213],"strict":[214],"constraints":[216],"input,":[219],"such":[220],"still":[225],"significant":[227]},"counts_by_year":[],"updated_date":"2026-07-03T08:13:44.112507","created_date":"2025-10-15T00:00:00"}
