KAN-Robust-Bench: A Benchmark for Evaluating the Robustness of Kolmogorov-Arnold Networks
研究通过随机平滑和区间边界传播方法,评估了Kolmogorov-Arnold网络模型在对抗逃避攻击下的鲁棒性,并探索了最佳防御策略。
研究通过随机平滑和区间边界传播方法,评估了Kolmogorov-Arnold网络模型在对抗逃避攻击下的鲁棒性,并探索了最佳防御策略。
This study investigates whether single-cell annotation methods can be misled by manipulating the composition of neighboring cells without altering the expression profile of target cells. To this end, we propose CohortHijack, a novel robustness auditing framework that reveals, for the first time, the query cohort composition as an attack surface that preserves target features. Our approach combines random and structured cell removal strategies with greedy, multi-start, and beam search algorithms to evaluate neighborhood- or clustering-based classifiers—specifically logistic regression and calibrated linear SVM—on the PBMC3K and Paul15 datasets. Experiments demonstrate that removing only a small fraction of non-target cells (average perturbation <0.4%) suffices to flip 19.67%–24.33% of target labels; this effect vanishes when neighborhood mechanisms are disabled, confirming the attack’s specific dependence on local cellular context.
This work proposes a human-AI collaborative, contestable care planning framework that addresses the limitations of traditional AI systems, which typically offer rigid recommendations without supporting clinicians’, patients’, or care teams’ ability to question and refine them. The framework employs a role-based argumentation graph mechanism integrated with multi-agent workflows to generate intervention recommendations alongside supporting and countervailing arguments. Human planners can review, revise, or augment these arguments before finalizing care plans. By incorporating role-aware argument generation and evaluation, adaptive care team recruitment, and dynamic scheduling, the system enables explainable plan generation, real-time team composition, and task orchestration in home-based eldercare settings. This approach significantly enhances the transparency, adaptability, and clinical accountability of care planning processes.
This work addresses the challenges of information heterogeneity and the lack of transparency and safety in large language models within multidisciplinary care coordination. To this end, the authors propose CANOE, a multi-agent neuro-symbolic framework that integrates role-based expert agents, arena-based quantified bipolar argumentation (QBAF), adaptive expert recruitment, and a human-in-the-loop correction mechanism. Notably, CANOE introduces, for the first time, an intervenable deterministic recomputation pipeline to yield clinical decisions that are explainable, contestable, and safe. Experimental results on the Discharge Me! and MedicalRAG datasets demonstrate that CANOE, when combined with medically fine-tuned language models, significantly enhances clinical correctness, safety, and interpretability, achieving strong performance across multiple metrics including ROUGE-L, AlignScore, and MEDCON F1.
This study addresses the vulnerability in adaptive electrocardiogram monitoring systems where clinically critical heartbeat classes are suppressed due to sensitivity to event sequencing. The authors propose a bounded event reordering attack that manipulates only the temporal order of genuine historical events—without altering waveforms, labels, or model outputs—to lower the confidence threshold for ventricular beats prior to evaluating a target event. Leveraging an adaptive conformal prediction framework, the method employs feasible permutation search under a displacement budget constraint to achieve precise reordering. Experiments on the MIT-BIH dataset demonstrate successful suppression of 66.7% and 60.0% of target events for Extra Trees and HistGradientBoosting models, respectively, substantially outperforming random scheduling (4.4% and 12.0%). Cross-dataset validity is further confirmed on INCART, revealing for the first time that merely manipulating event timing can compromise adaptive clinical monitoring systems.
研究通过随机平滑和区间边界传播方法,评估了Kolmogorov-Arnold网络模型在对抗逃避攻击下的鲁棒性,并探索了最佳防御策略。
This study investigates whether single-cell annotation methods can be misled by manipulating the composition of neighboring cells without altering the expression profile of target cells. To this end, we propose CohortHijack, a novel robustness auditing framework that reveals, for the first time, the query cohort composition as an attack surface that preserves target features. Our approach combines random and structured cell removal strategies with greedy, multi-start, and beam search algorithms to evaluate neighborhood- or clustering-based classifiers—specifically logistic regression and calibrated linear SVM—on the PBMC3K and Paul15 datasets. Experiments demonstrate that removing only a small fraction of non-target cells (average perturbation <0.4%) suffices to flip 19.67%–24.33% of target labels; this effect vanishes when neighborhood mechanisms are disabled, confirming the attack’s specific dependence on local cellular context.
This work proposes a human-AI collaborative, contestable care planning framework that addresses the limitations of traditional AI systems, which typically offer rigid recommendations without supporting clinicians’, patients’, or care teams’ ability to question and refine them. The framework employs a role-based argumentation graph mechanism integrated with multi-agent workflows to generate intervention recommendations alongside supporting and countervailing arguments. Human planners can review, revise, or augment these arguments before finalizing care plans. By incorporating role-aware argument generation and evaluation, adaptive care team recruitment, and dynamic scheduling, the system enables explainable plan generation, real-time team composition, and task orchestration in home-based eldercare settings. This approach significantly enhances the transparency, adaptability, and clinical accountability of care planning processes.
This work addresses the challenges of information heterogeneity and the lack of transparency and safety in large language models within multidisciplinary care coordination. To this end, the authors propose CANOE, a multi-agent neuro-symbolic framework that integrates role-based expert agents, arena-based quantified bipolar argumentation (QBAF), adaptive expert recruitment, and a human-in-the-loop correction mechanism. Notably, CANOE introduces, for the first time, an intervenable deterministic recomputation pipeline to yield clinical decisions that are explainable, contestable, and safe. Experimental results on the Discharge Me! and MedicalRAG datasets demonstrate that CANOE, when combined with medically fine-tuned language models, significantly enhances clinical correctness, safety, and interpretability, achieving strong performance across multiple metrics including ROUGE-L, AlignScore, and MEDCON F1.
This study addresses the vulnerability in adaptive electrocardiogram monitoring systems where clinically critical heartbeat classes are suppressed due to sensitivity to event sequencing. The authors propose a bounded event reordering attack that manipulates only the temporal order of genuine historical events—without altering waveforms, labels, or model outputs—to lower the confidence threshold for ventricular beats prior to evaluating a target event. Leveraging an adaptive conformal prediction framework, the method employs feasible permutation search under a displacement budget constraint to achieve precise reordering. Experiments on the MIT-BIH dataset demonstrate successful suppression of 66.7% and 60.0% of target events for Extra Trees and HistGradientBoosting models, respectively, substantially outperforming random scheduling (4.4% and 12.0%). Cross-dataset validity is further confirmed on INCART, revealing for the first time that merely manipulating event timing can compromise adaptive clinical monitoring systems.