Avalilação PREreview de Data Security in AI Healthcare Applications: Challenges and Innovative Methods
- Publicado
- DOI
- 10.5281/zenodo.21716444
- Licença
- CC BY 4.0
This review paper surveys defensive techniques for healthcare AI systems, focusing on blockchain, zero-knowledge proofs (ZKP), and honeypots as complementary approaches to address adversarial attacks, data poisoning, and data breaches. The authors synthesize 13 prior works into a comparative table and propose a conceptual hybrid security framework combining all three techniques, illustrated through a weighted mathematical scoring model. A qualitative use-case scenario is provided to demonstrate the proposed hybrid approach.
Major issues
1. Review methodology lacks rigor. The paper is positioned as a literature review but does not follow any established review methodology (PRISMA, SALSA, or comparable). Search databases are named but there is no documented inclusion/exclusion criteria, no time window justification, no quality appraisal of included works, and no data extraction protocol. As a result, the reader cannot assess whether the 13 cited works are representative of the field or how they were selected. A systematic or scoping review framework should be adopted, or the paper should be explicitly reframed as a narrative review with corresponding limitations acknowledged.
2. The "hybrid security score" model (Section 3.1–3.4) is not empirically grounded. The proposed equation S = αB + βZ + γH is a weighted average with arbitrarily chosen weights (α=0.4, β=0.4, γ=0.2) and arbitrarily chosen component values (B=0.85, Z=0.75, H=0.65). No justification is provided for how these values were obtained, what units they represent, or what a resulting score of 0.77 signifies. Without empirical calibration against real threat data or validation against a benchmark, this model does not "quantify" security in any meaningful sense it presents subjective weights as if they were measurements. Either an empirical basis for the weights should be provided (e.g., derived from threat frequency data, expert elicitation with documented methodology, or benchmarking against known attack outcomes), or the model should be explicitly reframed as an illustrative conceptual scaffold rather than a quantitative measure.
3. The "proposed solution" is not sufficiently detailed for evaluation. Figure 2 depicts blockchain, ZKP, and honeypots operating alongside a healthcare API, but the paper does not specify architectural details (which blockchain, permissioned vs. public, ZKP scheme used, honeypot deployment topology), integration points with existing healthcare infrastructure (HL7/FHIR, HIPAA-compliant messaging, EHR systems), performance considerations, or any implementation or evaluation. A reader cannot assess feasibility, scalability, or clinical workflow impact.
4. Regulatory and compliance context is absent. For a paper on healthcare data security, the omission of HIPAA (US), GDPR (EU), and analogous frameworks is a significant gap. There is no discussion of how blockchain immutability interacts with GDPR's right to erasure, how ZKP verification maps to HIPAA audit-logging requirements, or how honeypots relate to breach-notification obligations. These regulatory dimensions are central to any real-world deployment.
5. Key technical literature is missing. For a review on secure AI in healthcare, notable omissions include: federated learning (only mentioned in passing), differential privacy in medical data (Abadi et al. and follow-ups), homomorphic encryption implementations (mentioned in Table 1 but not discussed), secure multi-party computation, trusted execution environments (TEEs) such as Intel SGX in healthcare deployments, and standards work by NIST (SP 800-66) and HITRUST CSF. A review of only 13 works is thin for the breadth of the topic claimed.
6. Conflation of AI security with data security. The paper mixes adversarial ML attacks (data poisoning, model evasion — properties of AI systems) with conventional data breaches (unauthorized access, ransomware properties of any system holding sensitive data). These are related but distinct problem domains with different mitigation strategies. Separating these clearly and mapping each defensive technique (blockchain, ZKP, honeypot) to the specific threat class it addresses would strengthen the argument considerably.
7. Table 1 caption reads "This is a wide table" appears to be an unedited template placeholder. Similarly, Figure 3 caption references "your hybrid system" (second-person), suggesting incomplete editorial pass.
Minor issues
The introduction cites "275,000,000 individuals were affected by healthcare security breaches" in 2024 but provides no source. Please cite HHS OCR breach portal data or a comparable authoritative source.
Figure 1's "Robin Hoods" category of actors is unusual and not defined in the text. Either define this taxonomy explicitly or use standard threat-actor typologies (e.g., MITRE ATT&CK, or Verizon DBIR categories).
The funding statement references Grant No. 7502 for "Green Buildings and Environmental Monitoring Drone Swarms ECOSwarm." Please clarify how this grant relates to healthcare cybersecurity research, as the connection is not obvious.
Language editing is needed throughout.
The Discussion section (Section 3) largely restates points already made in Section 2 rather than synthesizing across the reviewed works. A synthesis matrix mapping threat class to defensive technique to open research questions would be more valuable.
References are limited (13). For a review paper on this topic, 40–60 references would be typical.
Competing interests
The author declares that they have no competing interests.
Use of Artificial Intelligence (AI)
The author declares that they did not use generative AI to come up with new ideas for their review.