طوّر باحثون من جامعات سعودية، بالتعاون مع باحثين دوليين، إطارًا تقنيًا لمراقبة حالات مرضى العناية المركزة، يجمع بين الذكاء الاصطناعي المصغر و«التوأم الرقمي» والتعلم الاتحادي، مع حماية البيانات بتقنيات تشفير مصممة لمقاومة الهجمات الإلكترونية وتهديدات الحوسبة الكمية.
ونُشرت الدراسة في مجلة «التقارير العلمية» التابعة لمجموعة سبرنغر نيتشر في يوليو الجاري، بمشاركة باحثين من جامعة طيبة، وجامعة الأميرة نورة، وجامعة القصيم، إلى جانب جامعة عبدالولي خان في باكستان.
وابتكر الباحثون نظامًا يسمح للمستشفيات بتدريب نموذج ذكاء اصطناعي مشترك دون نقل بيانات المرضى الخام أو جمعها في قاعدة مركزية واحدة، إذ يحتفظ كل مستشفى ببياناته محليًا ويرسل تحديثات النموذج فقط، في ما يعرف بالتعلم الاتحادي.
ويستهدف النظام أجهزة الاستشعار الطبية محدودة القدرة الحاسوبية داخل بيئة العناية المركزة، مستخدمًا نماذج تعلم آلي خفيفة يمكن تشغيلها على أجهزة صغيرة من فئة «إي إس بي 32»، بما يتيح تحليل المؤشرات الحيوية بالقرب من المريض وتقليل الحاجة إلى إرسال البيانات كاملة إلى خوادم خارجية.
وأُضيفت إلى النظام طبقة «توأم رقمي» مبسطة تحتفظ بآخر القراءات الفسيولوجية للمريض، واتجاهات الخطر بمرور الوقت، والتصنيف المتوقع للحالة، ومعلومات التنبيه التي يمكن تفسيرها. وأوضح الباحثون أن هذه الطبقة ليست محاكاة فسيولوجية كاملة لجسم المريض، بل تمثيل رقمي خفيف لحالته الصحية عند بوابة المستشفى.
واختُبر الإطار على بيانات اصطناعية لمراقبة العناية المركزة راجعها مختصون، ووزعت بين 3 مستشفيات افتراضية تختلف في خصائص بياناتها، ثم أُجري اختبار خارجي باستخدام بيانات رعاية حرجة مستمدة من قاعدة «فيزيو نت».
وصنّف النموذج الحالات إلى 5 فئات: طبيعية، وبسيطة، ومتوسطة، وحرجة، وحالات شاذة أو غير معتادة.
وفي الاختبار الخارجي، حقق النظام دقة بلغت 98.04%، وسجل قدرة على اكتشاف الحالات الحرجة بنسبة 97.7%، فيما بلغ مؤشر التمييز العام 0.999 من درجة كاملة. وتوضح هذه النتائج أداء النموذج على البيانات المستخدمة في الاختبار، ولا تمثل دقة سريرية مثبتة داخل مستشفيات فعلية.
مواجهة الهجوم الإلكتروني
اختبر الباحثون قدرة النظام على مواجهة هجوم إلكتروني يتعمد خلاله أحد الأطراف تغيير تصنيف الحالات الحرجة إلى حالات طبيعية، بهدف إفساد النموذج المشترك وإخفاء المرضى الأكثر تعرضًا للخطر.
وعند التعرض لهذا الهجوم، حققت آلية الحماية المقترحة دقة بلغت 86.79%، واحتفظت بقدرة على اكتشاف الحالات الحرجة بلغت 90.4%. وتعتمد الآلية على فحص أداء نموذج كل مستشفى واستبعاد النماذج المحلية منخفضة الجودة أو المشتبه في تعرضها للتلاعب قبل دمجها في النموذج العام.
تبادل مفاتيح التشفير
استخدم الباحثون تقنية «إم إل كيم 512» لتبادل مفاتيح التشفير، إلى جانب تشفير «إيه إي إس 256»، بهدف حماية تحديثات النماذج أثناء انتقالها بين المستشفيات. ولم تتجاوز الكلفة الزمنية الإضافية لطبقة التشفير 0.09 مللي ثانية لكل عملية تبادل.
وقال الباحثون إن الجمع بين الذكاء الاصطناعي المصغر والتعلم الاتحادي والتشفير المقاوم للحوسبة الكمية قد يدعم مستقبلاً بناء أنظمة مراقبة صحية تحافظ على خصوصية المرضى وتستمر في العمل حتى عند تعرض أحد مكوناتها لمحاولة اختراق أو تسميم للبيانات.
Researchers from Saudi universities, in collaboration with international researchers, have developed a technical framework for monitoring intensive care patients, combining micro artificial intelligence, "digital twins," and federated learning, while protecting data with encryption techniques designed to withstand cyber attacks and quantum computing threats.
The study was published in the journal "Scientific Reports" by Springer Nature in July, with contributions from researchers at Taibah University, Princess Nourah bint Abdulrahman University, and Qassim University, alongside Abdul Wali Khan University in Pakistan.
The researchers created a system that allows hospitals to train a shared artificial intelligence model without transferring raw patient data or collecting it in a central database, as each hospital retains its data locally and only sends model updates, in what is known as federated learning.
The system targets medical sensors with limited computing power within the intensive care environment, using lightweight machine learning models that can run on small devices of the "ESP32" class, enabling the analysis of vital signs close to the patient and reducing the need to send complete data to external servers.
A simplified "digital twin" layer was added to the system, which retains the latest physiological readings of the patient, risk trends over time, expected case classification, and interpretable alert information. The researchers clarified that this layer is not a complete physiological simulation of the patient's body, but rather a lightweight digital representation of their health status at the hospital gateway.
The framework was tested on synthetic data for intensive care monitoring reviewed by specialists, distributed among three virtual hospitals with varying data characteristics, followed by an external test using critical care data derived from the "PhysioNet" database.
The model classified cases into five categories: normal, mild, moderate, critical, and abnormal or unusual cases.
In the external test, the system achieved an accuracy of 98.04%, with a capability to detect critical cases at a rate of 97.7%, while the overall discrimination index reached 0.999 out of a perfect score. These results demonstrate the model's performance on the data used in the test and do not represent clinically validated accuracy within actual hospitals.
Countering Cyber Attacks
The researchers tested the system's ability to withstand a cyber attack in which one party deliberately changes the classification of critical cases to normal cases, aiming to corrupt the shared model and conceal the most at-risk patients.
When subjected to this attack, the proposed protection mechanism achieved an accuracy of 86.79% and maintained a capability to detect critical cases of 90.4%. The mechanism relies on assessing the performance of each hospital's model and excluding low-quality or suspected manipulated local models before integrating them into the overall model.
Encryption Key Exchange
The researchers used the "MLKEM 512" technique for exchanging encryption keys, along with "AES 256" encryption, to protect model updates as they transfer between hospitals. The additional time cost for the encryption layer did not exceed 0.09 milliseconds per exchange.
The researchers stated that the combination of micro artificial intelligence, federated learning, and quantum-resistant encryption could support the future development of health monitoring systems that maintain patient privacy and continue to operate even when one of their components is subjected to an attempted breach or data poisoning.