The Ontological Attack Surface: Measured Distortion Channels as Adversarial Primitives in Clinical AI

31 July 2026, Version 1
This content is an early or alternative research output and has not been peer-reviewed by Cambridge University Press at the time of posting.

Abstract

Security assessment of clinical AI has largely inherited the threat model of machine learning at large: adversarial perturbation of inputs, poisoning of training data, or manipulation of weights. This paper argues for a different, more tractable locus. In administrative clinical-AI pipelines, the attack surface is the set of measurable ontological distortion channels through which coded data already diverge from clinical reality, and each channel corresponds to an adversarial primitive an attacker can deliberately drive. We build the argument on a three-rung empirical substrate ladder. On synthetic data, a published adversarial cascade simulation (Synthea, n=1,000, 100 iterations) shows that a persistent low-magnitude stealth-ramp is the only configuration crossing the clinical-relevance threshold (total error 2.94 versus a 0.31 baseline), while single-shot high-magnitude injection reaches only 0.39; the exploitable surface is the feedback channel, not magnitude. On a real EHR (MIMIC-IV, 275 admissions, 4,506 rows), the distortion primitives are real, not artefacts: drift leaves 31.2% of assignments unspecified, set-membership rescue rises monotonically across comorbidity quintiles (0.44 to 0.94, Spearman ρ=0.39), and a substrate-determined false-positive floor of 25.8% survives any scoring. On routine primary-care data (23 practices, aggregate-only, non-invertible), a salient code (U07.1) carries an informativeness of 2.244 bits, the signature of salient-code overshadowing at scale. We map each channel onto a primitive from a six-class threat taxonomy, and derive a defensive corollary: because the channels are observable in non-invertible aggregates, the attack surface can be monitored without patient-level access.

Keywords

adversarial AI
clinical AI security
ontological attack
distortion channel
feedback loop
threat taxonomy
primary care
ontological integrity
supply-chain compromise
data quality

Comments

Comments are not moderated before they are posted, but they can be removed by the site moderators if they are found to be in contravention of our Commenting and Discussion Policy [opens in a new tab] - please read this policy before you post. Comments should be used for scholarly discussion of the content in question. You can find more information about how to use the commenting feature here [opens in a new tab] .
This site is protected by reCAPTCHA and the Google Privacy Policy [opens in a new tab] and Terms of Service [opens in a new tab] apply.