arXiv · 2610.09012
TwinGuard-Lite: A Rule-Based State-Admission Gateway for Generative Patient Digital Twins
Abstract
Future generative patient digital twins may combine longitudinal health records with language-model agents and keep information across sessions. The wording of a proposed update does not reveal whether it comes from an allowed source, conflicts with the patient's record, or belongs to someone else. We present TwinGuard-Lite, a rule-based gateway that admits an update to a twin's persistent state only if it passes checkable approximations of two integrity properties. Grounded state consistency (GSC) is approximated by a provenance check and a contradiction check; cross-patient noninterference (CPN) is approximated by a namespace check against trusted transport metadata. We evaluate three attack families over 20 seeded person-level splits of a semi-synthetic stream built from the openly licensed eICU database demo, with 29,131 $\pm$ 2706 candidate updates per seed. A keyword filter and an anomaly detector detect 16% and 24% of attacks, respectively; a provenance-only ablation detects 59.9% but misses every cross-patient attack. Combining GSC and CPN yields 99.1% precision, 90.5% recall, a 94.6% F1 score, and a 0.033% false-positive rate. Every attack the full gateway admits falsely claims a trusted source; when the retrieval channel does so, 92.9% of retrieval attacks are admitted. The results hold under stated trust assumptions, and no language model, agent, or retriever is executed: TwinGuard-Lite is a mechanism-level proof of concept that motivates authenticated, patient-bound ingestion, not a clinical safeguard.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Wenhui Chu, Sheikh Rabiul Islam. 2026-10-06. TwinGuard-Lite: A Rule-Based State-Admission Gateway for Generative Patient Digital Twins. https://arxiv.org/abs/2610.09012
Cite the original work for its findings. Save a collection to share your selection of sources.