Adversarial Resilience in Machine Learning Models Deployed on Connected Medical Devices
Keywords:
adversarial machine learning; medical device security; artificial pancreas; benchmark specification; robustness evaluation; resource-constrained inference; continuous glucose monitoring; regulatory scienceAbstract
Machine learning controllers now dose insulin inside closed-loop artificial pancreas systems. The adversarial machine learning literature has established that such models can be manipulated, and the author's own prior work catalogued this device class's attacks and candidate defences. This paper argues the missing artefact is a benchmark. Five structural gaps follow, each stated as what was not found rather than what does not exist: no empirical adversarial testing on real devices, no link from robustness to clinical harm, no validation of defences on constrained hardware, no regulator-aligned adversarial robustness testing standard, and almost no adversarial benchmarks for physiological time series. No systematic screening protocol was run, so no screening count exists. The gaps generate requirements forming a specification stratified along five axes: device tier, signal modality, patient stratum, threat model and clinical harm severity, with perturbation budgets in clinical units, resource cost alongside every robustness figure, and per-patient rather than cohort-mean results. Existing standards on neural network robustness, adversarial machine learning terminology and medical device safety and security risk management are engaged; none supplies the missing test method. The paper reports no adversarial robustness measurements, because none were performed. Its only empirical figures are anomaly-detection results from the author's separately published on-device detector, included strictly to illustrate honest on-device evaluation, not as evidence of adversarial robustness. The benchmark is specified, not instantiated: a minimum viable starting configuration is proposed so it can be built, and carries no results. Building it requires researchers, manufacturers and regulators to agree on the axes before arguing about the numbers.





