Abstract
Graph convolutional networks (GCNs) have been shown to be vul- nerable to small adversarial perturbations, which becomes a severe threat and largely limits their applications in security-critical sce- narios. To mitigate such a threat, considerable research efforts have been devoted to increasing the robustness of GCNs against adver- sarial attacks. However, current defense approaches are typically designed to prevent GCNs from untargeted adversarial attacks and focus on overall performance, making it challenging to protect im- portant local nodes from more powerful targeted adversarial attacks.
Additionally, a trade-off between robustness and performance is often made in existing research. Such limitations highlight the need for developing an effective and efficient approach that can defend local nodes against targeted attacks, without compromising the overall performance of GCNs. In this work, we present a simple yet effective method, named Graph Universal AdveRsarial Defense (Guard). Unlike previous works, Guard protects each individual node from attacks with a universal defensive patch, which is gener- ated once and can be applied to any node (node-agnostic) in a graph.
Guard is fast, straightforward to implement without any change to network architecture nor any additional parameters, and is broadly applicable to any GCNs. Extensive experiments on four benchmark datasets demonstrate that Guard significantly improves robustness for several established GCNs against multiple adversarial attacks and outperforms state-of-the-art defense methods by large margins.
S Concepts
• Computer systems organization →Embedded systems; Re- dundancy; Robotics; • Networks →Network reliability. Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than the author(s) must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission CIKM ’23, October 21–25, 2023, Birmingham, United Kingdom © 2023 Copyright held by the owner/author(s). Publication rights licensed to ACM.
Graph neural networks; Graph Adversarial Defense; Graph Adver-
Acm Reference Format:
Jintang Li, Jie Liao, Ruofan Wu, Liang Chen, Zibin Zheng, Jiawang Dan, Changhua Meng, and Weiqiang Wang. 2023. Guard: Graph Universal Ad- versarial Defense. In Proceedings of the 32nd ACM International Confer- ence on Information and Knowledge Management (CIKM ’23), October 21–25, 2023, Birmingham, United Kingdom. ACM, New York, NY, USA, 10 pages.
Ntroduction
Graph structured data are ubiquitous in real world, with promi- nent examples including financial networks , molecular finger- prints , and recommender systems . Graph convolutional networks (GCNs) , a series of neural network models primarily developed for graph structured data, have met with great success in a variety of applications and domains. This is mainly due to their great capacity in jointly leveraging information from both graph structure and node features. Over the past few years, research on GCNs has surged to become one of the hottest topics in deep learning community .
Despite the success of GCNs in numerous graph-based machine learning tasks, e.g., link prediction and node classification, they suffer seriously from vulnerability to adversarial attacks. As shown in [18, 36], slight perturbations on either node features or graph structure can lead to incorrect predictions of GCNs on specific nodes. This attack is also known as targeted attack . Even worse, has recently shown the possibility of misleading GCNs’ classifi- cation on “any” target node by performing a node-agnostic, universal adversarial perturbation.
The adversarial targeted attack is a real threat. For example, it provides a possibility of enabling a fraudster to disguise himself as a regular user to bypass GCNs based anti-fraud systems and disperse disinformation or reap end-users’ privacy . Hence, the need for countermeasures against such an attack becomes more critical. So far, heuristics have been investigated in the literature to mitigate the risk of adversarial attacks from different ways .
Among contemporary approaches, one of the most simple and ef- fective ways of defense is to preprocess the graph and alleviate the adversarial behaviors in advance. In this regard, first propose to remove suspicious edges between suspicious nodes based on
Arxiv:2204.09803V4 [Cs.Lg] 12 Aug 2023
CIKM ’23, October 21–25, 2023, Birmingham, United Kingdom Jintang Li et al. Jaccard similarity, leverage SVD to form a low-rank approx- imation of graph to reduce the effect of attacks. Current works can indeed protect GCNs from attacks toward the whole network.
Their defenses, however, are typically designed for the whole graph while ignoring the protection of important local nodes, making them suffer seriously from stronger adversarial targeted attacks. In addition, there is often a particular tradeoff between performance and robustness since they often hold the assumption that data has already been poisoned.
In this work, we consider a more practical and flexible defense strategy meant to generate what we term as universal defensive patch that can be applied to an arbitrary node. The defensive patch can be performed on the graph as an active defense, which mitigates the risk of adversarial attacks at test time by removing malicious edges from input graphs. Here a defensive patch is a 0-1 binary vector, where 1 denotes the edge modification (e.g., removal) and 0 otherwise. To our best knowledge, we are the first to study universal defense on graphs.
Why universal defense? As a new perspective of defense strat- egy, our work is orthogonal to recent studies on robustifying GCNs. The universal defense is advantageous as (i) no access to the target node or victim model is needed at test time, and (ii) it drastically lowers the barrier to defend against adversarial attacks: the uni- versal defensive patch is generated once and can be applied to any model (model-agnostic) and any node (node-agnostic) in a graph.
Is universal defense achievable? Although there have been several successful attempts in vision research, the possibility of a universal defense against adversarial targeted attacks on graphs remains largely unexplored. Particularly, graphs often come with complicated structures, in which relationships between nodes can be challenging to capture. As a result, achieving a universal defense may not be a straightforward task. In this paper, we seek to uncover the intrinsic patterns of adversarial attacks, and one step further, explore the feasibility of universal defenses on graphs. Specifically, we empirically discover an interesting phenomenon that attackers prefer picking the same attacker nodes from a set of low-degree nodes when perturbing different target nodes. The finding suggests that these nodes may be part of what makes the model vulnerable, and thus a universal defense becomes possible if one can identify them in advance.
In light of above insights, the core problem we raise and address
In This Paper Is:
How to design a universal defense that works for any individual node
To Defend Against Adversarial Attacks?
In this paper, we propose Graph Universal AdveRsarial Defense (Guard) to address this problem for the first time. Unlike previous works, Guard applies a universal patch to protect any node from adversarial targeted attacks without knowledge of victim GCNs.
We empirically show that our method can significantly improve the robustness of victim GCNs against a variety of adversarial targeted attacks. Particularly, we demonstrate that GCNs equipped with Guard can also outperform current state-of-the-art defenses with large margins.
This paper offers the following main contributions: • We demonstrate, both theoretically and empirically, that current attacks tend to perturb a target node with a fixed set of low-degree nodes. Our finding offers deeper insights on understanding the vulnerability of GCNs.
• We propose Guard, an effective and scalable universal de- fense to protect an arbitrary node from multiple adversarial attacks. Guard comes with good generality and flexibility for well-established GCNs, enabling them to be robust against adversarial attacks.
• Extensive experiments on four public graph benchmarks demonstrate that Guard can protect GCNs from strong ad- versarial targeted attacks without sacrificing the clean per- formance.
To our best knowledge, Guard is the first successful attempt in applying universal defense on graphs. We believe that our work is a step forward in the development of simple and provably effective defenses, and hope that it will inspire both theoretical and practical future research efforts.
Related Work
The robustness of graph convolutional networks against adversarial attacks has gained increasing attention in the last few years [4, 17, 18, 35–37]. While there are numerous (heuristic) approaches aimed at robustifying GCNs, there is always a newly devised stronger attack attempts to break them, leading to an arms race between attackers and defenders .
Adversarial attack on graphs. Literature is rich on attacking GCNs with adversarial examples. The most widely used solution for crafting adversarial examples on graphs is to utilize a locally trained surrogate model (typically a GCN) . In this way, an attacker obtains the approximated gradient/loss towards edges or edge modifications in a graph [2, 7, 27, 37] or subgraph to craft the worst-case perturbations, and subsequently transfer them to other victim models as a practical gray-box attack. These surrogate- based attacks have become a serious threat to GCNs because they are able to attack the target GCNs without requiring sufficient knowledge of them.
Adversarial defense on graphs. Extensive research efforts have been made on improving the robustness of GCNs, which can be typically classified into three categories: (i) robust training (e.g., adversarial training) [16, 29], (ii) model robustification that focuses on either the message passing scheme or the network architec- ture [4, 12, 35] and (iii) graph preprocessing [6, 27]. A general drawback shared by previous methods is the lack of scalability, which makes them less capable of dealing with graphs that are sub- stantially larger than PubMed . In addition, the aforementioned defenses primarily aim to mitigate attacks on the entire network, rather than protecting GCNs from local targeted adversarial attacks.
Universal attack and defense. Recent works show a new trend of attacking neural networks by universal adversarial attacks [20, 31], i.e., unique perturbations that transfer across different inputs. The universal attacks have been widely studied in vision research. Until recently, first extend the idea to graph domain by crafting a single and universal perturbation that is capable to fool a GCN when applied to any target node. Another line of research is universal defense, which devises a universal ‘watermark’ to protect neural networks from multiple attacks . Despite the recent interest
Guard: Graph Universal Adversarial Defense
CIKM ’23, October 21–25, 2023, Birmingham, United Kingdom in problems of universal defense among vision research, there has been relatively little work that explores the universal defense in the graph domain.
Notations
In line with the focus of our work, we briefly outline necessary definitions used throughout this paper. Let G = (V, E) be an undi- rected graph, with the node set V = {𝑣1, . . , 𝑣𝑁} and the undi- rected edge set E = {𝑒1, . ,𝑒𝑀}. The corresponding adjacency matrix is denoted as 𝐴∈{0, 1}𝑁×𝑁with (𝑢, 𝑣) entry equaling to 1 if there is an edge between 𝑢and 𝑣and 0 otherwise. We denote 𝑑
𝑣𝐴𝑢,𝑣. Also, Each Node Is Associated
with an 𝐹-dimensional feature vector and 𝑋∈R𝑁×𝐹denotes the feature matrix for all 𝑁nodes. In the node classification task, each node 𝑣is associated with one class label 𝑦𝑣∈C where C is the set of all candidate classes. Given a subset of nodes Vtrain ⊂V are labeled, the goal is to learn a function 𝑓𝜃that maps each node 𝑣∈V to exactly one of the classes in C.
Graph Convolutional Networks
We introduce the well-established multi-layer GCN for node
where ˜𝐴= 𝐴+ 𝐼𝑁denotes the adjacency matrix with self-loop and the corresponding degree matrix is ˜𝐷. 𝐻(0) = 𝑋and 𝜎is the activation function such as ReLU. For the 𝑙-th graph convolutional layer, we denote the node embeddings by 𝐻(𝑙) and the learnable weight by 𝑊(𝑙).
Without loss of generality, we consider a two-layer GCN with ReLU activation in the hidden layer, which is commonly used in
Et 𝑓𝜃represent A Gcn Model With Learnable
parameters denoted as 𝜃= {𝑊(0),𝑊(1)}. The optimal parameters 𝜃are learned by minimizing cross-entropy on the output of the
Adversarial Targeted Attack
Below, we present the definition of adversarial targeted attack under the scenario of evasion (test-time) attack. Note that it is straightfor- ward to extend the definition to adversarial untargeted attacks by suitably modifying the loss function.
Definition 1 (Adversarial targeted attack). Given a graph G = (V, E), the goal of an attacker is to craft a perturbed graph G′ = (V′, E′) within a budget Δ, and mislead the output of GCNs on a target node 𝑢. The adversarial attack on GCNs can be
G′∈Φ(G) L𝑢(𝑓𝜃(𝐴′,𝑋)),
where 𝐴′ is the perturbed adjacency matrix that represents the graph G′, Φ(G) represents the set of all possible modified graphs that are constrained by the attack budget Δ.
Typically, an attacker aims to find a perturbed graph G′ that classifies target node 𝑢as 𝑦′𝑢such that 𝑦′𝑢≠𝑦𝑢, which is equivalent to maximizing the cross-entropy loss of the GCNs’ output on 𝑢.
According to [18, 36], the perturbation can be performed on the targeted node 𝑢or its neighborhoods, resulting in direct attack or indirect/influence attack, respectively. In this paper, we mainly consider the direct attack as it is more powerful than the indirect attack [4, 18, 36].
As an attacker usually has no access to the target model in a practical scenario, they instead train a surrogate model 𝑓𝜃∗(𝐴,𝑋) locally and utilize the approximated loss L∗≈L to find the worst- case perturbations. The attack is also called surrogate attack .
Universal Defense On Graphs
We briefly outline necessary definitions of universal defense, a newly studied defense strategy on graphs. In this work, the term universal means applicable to any node , differs from that appli- cable to any image in vision research .
A universal defense mainly focuses on edge-injection attacks since (i) attackers tend to add edges between dissimilar nodes and (ii) injection is an operation with stronger attack power compared with deletion, the conclusions reached in prior studies [4, 27]. We provide further discussion in Section 5. The core idea of universal defense is to generate a unique patch 𝑝— a length-𝑁binary vector 𝑝, where 1 indicates an attacker node1 and 0 otherwise. Without loss of generality, we denote these attacker nodes as A and term them as anchor nodes, a set of important nodes that may be potentially used for attack. The universal patch 𝑝is only computed once and can be applied to any node. When applied to a node 𝑢, the universal patch removes all potential adversarial edges (if exist) that are connected
where ◦is the element-wise product, 𝑃∈{0, 1}𝑁×𝑁is a derived matrix with the 𝑢-th row and 𝑢-th column replaced by the patch vector 𝑝. The element (𝑖, 𝑗) in 𝑃equals 1 indicates the corresponding edge (𝑖, 𝑗) ∈E is to be removed (if exists). Let G(𝑢) = (V, E′) denote the modified graph and 𝐴′ the corresponding adjacency matrix w.r.t. target node 𝑢, an effective defense should directly prune all of the malicious edges and mitigate the adversarial effects, while ensuring that the benign edges and downstream performance are not compromised.
Figure 1 illustrates the universal defense in the context of adver- sarial targeted attacks. In this case, a targeted attack aims at fooling GCNs on a specific node 𝑣1 by modifying the graph structure. The universal defense, in contrast, generates a universal defensive patch 𝑝which could be applied to any nodes to defend against adversarial attacks. We will elaborate in the next section an algorithm to find such 𝑝, or in other words, to identify the anchor nodes A.
1An attacker node is a maliciously added neighbor for a target node to achieve the
Adversarial Goal
CIKM ’23, October 21–25, 2023, Birmingham, United Kingdom Jintang Li et al.
𝐴′ = 𝐴∘(1 −𝑃)
Figure 1: An illustrative example of graph universal defense. The universal patch 𝑝can be applied to an arbitrary node (here 𝑣1) to protect it from adversarial targeted attacks by removing adversarial edges (if exist).
Present Work
In this section, we draw on the insights from the literature reviewed in Related Work, and empirically investigate the intrinsic patterns of adversarial attacks on graph data. Then, we analyze possible reasons to understand the observations and further introduce our proposed method.
Attacks
In this subsection, we begin with an empirical study on Cora and PubMed (dataset statistics are listed in Table 1). Specifically, we attack different target nodes in the test set with three advanced surrogate attacks: SGA , FGA and IG-FGSM (IG) , which craft the worst-case perturbations by leveraging the surrogate gra- dients in different ways. The perturbation budget for each target node is set as its degree, following [18, 36].
We perturb different nodes with these attacks and count the frequency of each node selected as an attacker node, i.e., picked for adversarial edges. We plot the frequency (in descending) of all nodes on both datasets in Figure 2.
Observation I. Attackers tend to connect the target node to a fixed set of attacker nodes, which also exhibits long-tailed distribu- tions with a heavy imbalance in the measured frequency. As a result, the top-50 nodes with the highest frequencies account for nearly 90% and 80% of the frequencies on both datasets, respectively.
Next, we plot the degree distribution of these high-frequency attacker nodes in Figure 3. Observation II. Most of the attacker nodes are low-degree nodes (i.e., degree ≤2), and the phenomenon is more obvious on PubMed.
The results suggest that adversarial edges tend to link the target node with low-degree nodes, and almost half of them are below 2 degrees. In other words, the low-degree nodes are more likely to be maliciously added neighbors for a target node.
We will offer a further explanation on these findings in the next subsection. Figure 2: Frequency of top-500 selected attacker nodes by different attacks on Cora and PubMed datasets. The top-50 nodes account for almost 90% and 80% of the frequencies on both datasets, respectively.
Figure 3: Degree distribution of top-500 selected attacker nodes by different attacks on Cora and PubMed datasets, respectively.
Guard: Universal Defense On Graphs
The observation that a fixed set of low-degree nodes account for most of the measured frequencies is surprising. This gives imme- diately rise to a fundamental question: can we achieve a universal defense for an arbitrary node by uncovering these attacker nodes at test time? In the following, we will address this question with our proposed Guard.
Recall that an optimal attack is typically achieved by exploiting the vulnerability of a locally trained surrogate model, which de- termines the (approximately) optimal perturbations by taking the gradient of the surrogate loss L∗w.r.t. the adjacency matrix 𝐴. The largest magnitude of the gradient can be seen as a relaxation of the worst-case perturbation determined in the brute force method.
Without loss of generality, we make the following assumption: Assumption 1 (Optimal surrogate attack). Given a tar- get node 𝑢, the worst-case perturbation (modification) on 𝑢is an edge (𝑢, 𝑣) with the largest magnitude of gradients 𝑔𝑢,𝑣, where 𝑔=
𝑢
𝜕𝐴] ∈R𝑁×𝑁is the gradient matrix. Assumption 1 can be easily satisfied and has been hold empiri- cally in current works [2, 18, 27]. As we focus on the case of edge- injection attacks, the key to identifying attacker nodes is to find the edges corresponding to the maximum value of the gradients.
Proposition 1. For simplification, let us consider a 1-layer GCN with output 𝑍= Softmax( ˆ𝐴W) where W = 𝑋𝑊. Given a target
Guard: Graph Universal Adversarial Defense
CIKM ’23, October 21–25, 2023, Birmingham, United Kingdom where (𝑢, 𝑣∗) denotes the edge corresponding to the largest gradient 𝑔𝑢,𝑣∗and N (𝑢) is the set of nodes adjacent to 𝑢.
We give below the proof of Proposition 1. Proof. The forward inference at the l-layer GCN is formally
For a target node𝑢, attackers aim to find the worst-case perturbation with the approximated loss L∗𝑢= −ln𝑍𝑢,𝑦𝑢. Taking derivatives by
Following the chain rule of gradient backpropagation in terms of the adjacency matrix 𝐴, it is easy to calculate the gradient of each edge (𝑢, 𝑣) in the graph, or the element (𝑢, 𝑣) in 𝑔:
Where ˆ𝑔𝑖,𝑗= [𝜕L∗𝑢/ ˆ𝐴]𝑖,𝑗= Í
𝑐∈C 𝑍𝑖,𝑐W𝑗,𝑐−W𝑗,𝑦𝑖. According to Eq.(7), the determining term of 𝑔𝑢,𝑣for different nodes 𝑣is ˆ𝑔𝑢,𝑣/√𝑑𝑣since 𝑣∉N (𝑢) and other terms are constants for a fixed target node 𝑢. For an edge (𝑢, 𝑣∗) with the largest value
The desired result is attained.
□
Remark 1. Essentially, it is shown in Proposition 1 that the mag- nitude of gradient 𝑔𝑢,𝑣is determined by the term (Í
𝑐∈C 𝑍𝑣,𝑐w𝑣,𝑐−
W𝑣,𝑦𝑢)/√𝑑𝑣. That said, a node with a lower degree is more likely to be a maliciously added neighbor for a target node under Assumption 1. Proposition 1 is basically built on a 1-layer GCN, we made this mild assumption to simplify our discussion and should not affect our findings. The result still holds for an 𝑙-layer GCN, where W is computed by collapsing weight matrices between consecutive layers, i.e., W = 𝑋·𝑊(0) · · ·𝑊(𝑙−1).
Remark 2. For any two target nodes 𝑢1 and 𝑢2, let 𝑒∗
= (𝑢2, 𝑣∗
2) be two edges corresponding to the largest gradients
= 𝑣∗
2 if W𝑣1,𝑦𝑢1 ≈W𝑣2,𝑦𝑢2 . The result is straightforward from Proposition 1. The condition W𝑣1,𝑦𝑢1 ≈W𝑣2,𝑦𝑢2 is often satisfied, since many modern neural networks are typically overconfident in their predictions . That is, they often produce a high confidence probability for the predicted class, while treating all others equally with an equally low probabil- ity. The overconfidence issue of GCNs is also revealed in and still holds for the linear part W. In other words, attackers would pick the same node when attacking different target nodes, which is in line with our empirical results in Figure 2.
Algorithm 1 Graph Universal Adversarial Defense
Input: Graph G = (V, E); node features 𝑋and degrees 𝑑; labeled nodes set Vsub, weight matrix𝑊, target node𝑢, hyperparameters
𝑘and 𝛼;
Output: Purified Graph G(𝑢) = (V, E′) for target node 𝑢;
: I∗(𝑣) ←0, ∀𝑣∈V;
⊲Initialize node influence score.
: Return G(𝑢) = (V, E′);
Intuitively, for an edge to inject, we can determine how impactful that change was by looking at the gradient w.r.t. the adjacency matrix 𝐴. According to Proposition 1, we measure the sensitivity of node 𝑢to node 𝑣, or the influence of 𝑣on 𝑢, by measuring the determining part of the gradient corresponding to the edge (𝑢, 𝑣).
For a target node 𝑢, the influence score I𝑢(𝑣) captures the relative influence of node 𝑣on 𝑢, when 𝑢being a target node:
where 𝛼is a scaling factor that controls the impact of node de- gree and 𝛼= 0.5 for a standard case in Proposition 1. W can be easily obtained by training a surrogate SGC or linear GCN locally.
Note That Í
𝑐∈C 𝑍𝑣,𝑐= 1, we use the upper bound of I𝑢(𝑣) as the approximated influence score for the ease of computation:
By using the upper bound of I𝑢(𝑣), we can hereby reduce the computational complexity of our approach while still achieving a reasonable approximation of the true influence score.
To simulate the attacks on different target nodes 𝑢, we can com- pute the influence distribution of all nodes based on a subset of labeled nodes Vsub ⊆Vtrain, by averaging the influence score I𝑢(𝑣)
Under Assumption 1, the node with the highest influence score is the most likely to be an attacker node. Therefore, we derive the
Set Of Anchor Nodes (Size 𝑘) As:
A = {𝑣| I∗(𝑣) is 𝑘-largest}.
There is a trade-off between performance and robustness, with a larger 𝑘would result in a better defense, but might sacrifice predic- tive accuracy on clean graphs as it removes a large proportion of edges. The detailed algorithm of Guard is described in Algorithm 1.
Authors:
Peder EZ Larson 1, 2,* , Jenna ML Bernard1, James A Bankson 3, Nikolaj Bøgh 4, Robert A Bok1, Albert P. Chen 5, Charles H Cunningham 6,7, Jeremy Gordon1, Jan-Bernd Hövener 8, Christoffer Laustsen 4, Dirk Mayer 9,10, Mary A McLean11 12, Franz Schilling13, James Slater1, Jean-Luc Vanderheyden5, 14, Cornelius von Morze 15, Daniel B Vigneron1, 2, Duan Xu1, 2, and the HP 13C
94143, Usa.
Denmark. 5 GE Healthcare, Menlo Park, California, USA. 6 Physical Sciences, Sunnybrook Research Institute, Toronto, Ontario, Canada.
8 Section Biomedical Imaging, Molecular Imaging North Competence Center (MOIN CC), Medicine, Baltimore, MD, USA. Cambridge, United Kingdom.
14Jlvmi Consulting Llc, Dousman, Wi, Usa
#See Acknowledgements for a list of all HP 13C MRI Consensus Group Members This work was supported by the ISMRM Hyperpolarized Media MR Study Group, the ISMRM Hyperpolarization Methods & Equipment Study Group, and the Hyperpolarized MRI Technology Resource Center (NIH/NIBIB grant P41EB013598).
Abstract
MRI with hyperpolarized (HP) 13C agents, also known as HP 13C MRI, can measure processes such as localized metabolism that is altered in numerous cancers, liver, heart, kidney diseases, and more. It has been translated into human studies during the past 10 years, with recent rapid growth in studies largely based on increasing availability of hyperpolarized agent preparation methods suitable for use in humans. This paper aims to capture the current successful practices for HP MRI human studies with [1-13C]pyruvate - by far the most commonly used agent, which sits at a key metabolic junction in glycolysis. The paper is divided into four major topic areas: (1) HP 13C-pyruvate preparation, (2) MRI system setup and calibrations, (3) data acquisition and image reconstruction, and (4) data analysis and quantification. In each area, we identified the key components for a successful study, summarized both published studies and current practices, and discuss evidence gaps, strengths, and limitations. This paper is the output of the “HP 13C MRI Consensus Group” as well as the ISMRM Hyperpolarized Media MR and Hyperpolarized Methods & Equipment study groups. It further aims to provide a comprehensive reference for future consensus building as the field continues to advance human studies with this metabolic imaging modality.
Keywords: Hyperpolarized MRI, metabolic imaging, carbon-13, pyruvate, dissolution dynamic
Introduction
MRI with hyperpolarized 13C agents, also known as hyperpolarized (HP) 13C MRI, has shown great potential as a novel imaging modality, particularly for its ability to probe metabolic processes in real time. The first human studies with HP [1-13C]pyruvate were performed in 2011 in prostate cancer patients (1).
Since then, there have been over 60 papers published with imaging results of human subjects from 13 different sites, with applications including prostate cancer, brain tumors, breast cancer, kidney cancer, pancreatic cancer, metastatic disease, liver disease, ischemic heart disease, diabetes and cardiomyopathies. The vast majority of these studies used [1-13C]pyruvate (1–63), where [2-13C]pyruvate (64) and 13C-urea (56) have been demonstrated too.
As clinical HP 13C MRI advances, there is a growing need to build consensus for best practices, which are critical for comparing data across sites, performing multi-site trials,deploying methods to new sites, partnering with vendors, and potentially for obtaining broader regulatory approvals.
In March 2022, we initiated an effort to build consensus within the HP 13C MRI community with this opportunity in mind, and it was greeted with strong enthusiasm. The “HP 13C MRI Consensus Group”, containing over 55 members from 27 sites, identified the area of greatest need and opportunity for consensus building to be HP [1-13C]pyruvate human
●
Pyruvate is the most mature and widely used HP agent and has the most significant translational evidence emphasizing the potential clinical impact.
●
Clinical trials, particularly multi-site trials, have the strongest need for consensus methods to ensure that data can be combined across sites. This work is a Position Paper for which the goal is to describe current successful practices and study methods for HP [1-13C]pyruvate human studies along with justification to support those practices. This is divided into four major topic areas: (1) HP 13C-pyruvate preparation, (2) MRI system setup and calibrations, (3) data acquisition and image reconstruction, and (4) data analysis and quantification (Fig. 1). The current successful practices and study methods include a literature review of published peer-reviewed journal papers showing human HP [1-13C]pyruvate study data, up to September 2022 (1–63), as well as new unpublished information from surveys of HP 13C study sites. Based on this information, we also highlight the evidence gaps, strengths, and limitations of current practices which are summarized at the end of each section.
Figure 1: Illustration of the HP 13C MRI human study process, including the 4 major areas covered in this paper: Hyperpolarized 13C-pyruvate preparation, MRI system setup and calibration, Acquisition and Reconstruction, and Data Analysis and Quantification.
Figure 2: Anatomical targets of HP [1-13C]pyruvate MRI human studies published up to September 2022.
Hyperpolarized 13C-Pyruvate Preparation
This section covers the processes for creating the HP agent, 13C pyruvate, and will include many aspects and considerations that are needed to safely and effectively prepare doses for metabolic imaging studies in human subjects. These include material, personnel, equipment and facility, fluid path preparation, quality control, and release.
It is helpful to understand that the specifications of a dose of 13C pyruvate suitable for in vivo MR HP metabolic imaging were shaped in part by early preclinical studies performed by GE HealthCare summarized in Ref. (65). In short, the safety of the two novel drug components, 13C pyruvate and the electron paramagnetic agent (EPA) AH111501, were demonstrated in those studies. The more precise formulation of the dose suitable for human use was then determined from clinical studies (66) that included two Phase 1 clinical trials in young and elderly healthy volunteers without hyperpolarization of the 13C nuclei and another Phase 1/2a dose escalation and imaging feasibility study with HP 13C pyruvate in 31 prostate cancer patients at the With the exception of the first HP 13C imaging clinical trial, which utilized a prototype device in a cleanroom (1), all HP 13C studies performed in humans to date have utilized the SPINlab polarizer (manufactured by GE HealthCare). Consequently all doses of the HP 13C pyruvate delivered by SPINlab have been produced using the “SPINlab Pharmacy Kit” that serves as the container-closure system for the various drug components (13C pyruvic acid and EPA mixture, dissolution medium, and neutralization and dilution medium) during sample polarization, dissolution and quality control (QC) processes. Thus many aspects of the HP sample preparation considerations discussed below are related to the SPINlab instrument and the consumables designed to be used with it (67).
General Considerations
While more than 860 patients or healthy subjects having been injected with HP 13C pyruvate as of January 2022 without reports of any serious adverse events (68), HP 13C pyruvate injection remains an investigational MR contrast agent and can only be administered by those with Investigational New Drug (IND) exemption from the Food and Drug Administration (FDA) in the USA, a Clinical Trial Application (CTA) in Canada, approval from National Research Ethics Committee Services in the UK, or approval from the relevant local regulatory body. Thus, methods and processes involved to produce a dose should have patient safety as the first priority. Since utilizing dissolution dynamic nuclear polarization (dissolution-DNP) for human use is still a relatively new development, there are no existing published regulatory guidelines specifically for this method.
There are two major production styles that determine how various sites approach the agent preparation. In the US, the most common approach is to rely on a sterilizing filter (“Terminal Sterilization”) to ensure sterility of the final product, akin to PET tracer production, where a starting molecule with a radioisotope is processed using various other ingredients to make the final, desired and injectable contrast agent within a necessarily short amount of time (69). For these sites, sterilization of the components and accessories upstream of this filter are not required, although many of them were manufactured and tested following Good Manufacturing Practice (GMP) or Good Laboratory Practice (GLP) requirements. The filling process is usually performed under an ISO 5 laminar flow hood, but a clean room or an isolator is not required.
This approach is typically accompanied by testing the integrity of the sterilizing filter prior to release of the dose for injection. Typically, post release endotoxin and sterility tests are performed using an aliquot reserved from each released dose.
In the UK and EU, the most common approach is to more-closely follow sterile pharmaceutical compounding guidelines (70), where all components and ingredients are required to be sterile or manufactured under GMP guidelines and are assembled and filled within a clean room environment or an isolator system (“Sterile Preparation”). Typically a batch of Pharmacy Kits for HP 13C pyruvate injection are prepared together. The sterility of the final dose is also ensured by batch validation testing, in addition to the sterility of the ingredients and the sterile compounding process. The endotoxin and sterility testing are performed for the process validation but are not performed for each injected dose.
Some institutions fill and assemble the Pharmacy Kit required for a specific study on the same day or the day prior to polarization, dissolution, and patient administration, but others have also demonstrated the feasibility of preparing a batch of kits, keeping them in a -20ºC freezer and using them over a period of a few months.
Beyond the obvious requirements that the process and the facility has to ultimately produce a dose that is safe to inject into a human, regulatory authorities will also focus on the question “Are you in control of your processes?”. To be in control of your process requires an in-depth and broad understanding of all processes involved in pre, post, and during the production process.
Personnel
It is typical and may be required to have licensed personnel involved in the production process depending on local regulations.Typically a pharmacist, radiopharmacist or other similarly qualified person (QP), in charge of the facility where the Pharmacy Kit filling and preparation is taking place, is responsible for the overall process and the release of the injectable dose.
Qualified cleanroom technicians are often involved in the Pharmacy Kit filling under the supervision of the pharmacist or QP. As is required for pharmaceutical compounding or PET tracer production, training requirements and training records for all personnel need to be maintained and available for audit by the FDA or equivalent.
Equipment And Facility
The facility and all equipment need to have standard operating procedures (SOPs) that describe how equipment is used, maintained, and calibrated to comply with relevant legislation. Currently, almost all the filling of the Pharmacy Kit takes place within a compounding laminar flow hood or isolator (typically ISO 5). At some sites, the filling is conducted within a cleanroom, while at others, it is conducted in a dedicated non-cleanroom space, reflecting differences in cleanroom approach and specifications between regulators worldwide (71). Some equipment or facilities, such as the compounding hood or cleanroom, may require external certified laboratories for testing.
Material Handling
Material handling guidelines (69,70) require SOPs detailing a system to track all of the materials involved in the HP production process for a particular patient dose, similar to current good manufacturing practice (cGMP) requirements for material handling for drug compounding. This includes acceptance standards, storage conditions, amount used in the patient dose for each ingredient and materials used in the assembly of the fluid path and Pharmacy Kit. Currently some users choose to open and inspect and sometimes modify the Pharmacy Kits upon arrival, but some users keep them in the sealed packaging until they are required for dose preparation.
Pharmacy Kit Filling And Assembling
As required by an IND or its equivalent, the preparation of the doses of HP 13C agent are detailed in the Chemistry, Manufacturing, and Control (CMC) section of an applicable regulatory submission; an example of this has been made available (72). It describes the processes of filling the Pharmacy Kit with the different components that make up the final drug product, and of assembling the final kit for either storage or immediate use in the polarizer. Special attention should be given to the laser welding process in order to satisfy installation qualification (IQ) and operational qualification (OQ). Typically, the final developed process is validated by process qualification (PQ) runs, during which 3 or more Pharmacy Kits are filled and used and the final HP 13C products are tested for endotoxin and sterility and to confirm that they meet the dose specifications for injections (usually including pyruvate concentration, residual EPA concentration, pH, liquid state polarization level and dose temperature). The data from 3 consecutive PQ runs are submitted as part of the IND submission (or its equivalent), and are often also reviewed by the Institutional Review Board (IRB) where the studies are conducted.
Quality Control And Dose Release
The quality control (QC) and dose release can be separated into two aspects: one is the QC and release of the filled Pharmacy Kit, and second is the QC and release of the HP 13C agent for injection, after polarization and dissolution. For institutions filling a batch of kits and storing them to use over a period of time, typically the batch can be released based on initial validation, environmental monitoring data from the day of kit production, and if filters are used during preparation of any of the components, filter integrity testing. But in some cases one or more kits are used for validation before the batch of kits are released for future use. For institutions that fill only the kits required for specific studies shortly before the experiment, the filled kits often do not go through separate release tests before they are used.
The quality control of the HP 13C pyruvate solution post dissolution is primarily performed to ensure that the agent meets the dose specifications (Table 1) before it is administered to the subject. These specifications target both safety (pH, residual EPA, temperature) and efficacy (pyruvate concentration, polarization, volume). Typically, the pyruvate concentration, residual EPA concentration, pH, dose temperature, dose volume, and liquid state polarization are measured by the QC accessory associated with the SPINlab polarizer. Some users perform a secondary measurement for one of the parameters, such as pH, using a different instrument or pH paper. For sites that do not go through a separate release testing process for batch filled kits, the integrity of the sterilization assurance filter, a part of the Pharmacy Kit, is typically tested as a part of the dose release. It is also common for these users to preserve an aliquot of the final HP 13C pyruvate solution for post-release endotoxin and sterility testing. This testing cannot be completed fast enough to test an individual dose prior to injection, but this is why other processes such as PQ runs and validation testing are done to minimize the chance a subject could be injected with a contaminated dose.
The Final Dose Release And Injection
should be done under the supervision of a licensed professional, based on local regulations.
Some Key Challenges
Many of the challenges associated with HP 13C pyruvate preparation can be attributed to the conditions required for the dissolution-DNP method of high magnetic field (~3-7 T) and very low temperature (~1 K) during polarization, with pressurized and superheated water necessary for the rapid dissolution event. These extreme conditions are quite challenging for the design of the container-closure and fluid path system. In particular, the cryogenic temperature in the polarizer requires special attention to any moisture or ambient (moist) air introduced into that portion of the fluid path, which can form an ice block at ~1 K. This ice can lead to flow restriction during the dissolution event and reduce the strength of the laser welded bond between the cryovial and its cap. This can ultimately produce failures in the dissolution step, including variations in final pyruvate concentration and pH that may fail to meet QC release criteria as well as fluid path ruptures that provide no available dose and result in polarizer down-time.
The polarization of the HP 13C pyruvate sample decays quickly over the span of a few minutes after dissolution, and thus the process of dissolution, QC for release, and injection should be completed as fast as possible to preserve the high polarization level achieved. Any delays in the preparation process, such as transportation time or equipment malfunction, can significantly reduce the final polarization and result in lower quality imaging data.
Current Practices
A summary of data collected from all sites performing clinical trials with HP 13C-pyruvate is shown in Fig. 3 and Table 1, including the specification of the final dose and how the quality control and release of the final dose are performed. There is a split in the Production Style, described in the General Considerations section above, with 8/13 sites using Sterile Preparation versus 5/13 using Terminal Sterilization. While many of the dose specifications show notable differences in acceptable ranges, all of these variations listed in tables have been successfully and safely been used to perform HP 13C pyruvate studies in humans. Their differences depend on the institutions’ preferences, resources and their particular regulatory situation. There is high similarity in pyruvate ranges, temperature ranges, EPA limits, and volume limits. There is modest variability in pH ranges and large variability in the endotoxin test limit. There is a 3-fold difference in acceptable polarization levels, which are measured to ensure a futile dose is not injected since the polarization is directly proportional to SNR. This reflects the decision by several sites to believe that useful data can be still be obtained with suboptimal polarizations.
Figure 3: Hyperpolarized agent preparation methods reported by sites currently performing HP
In House
Table 1: HP 13C-pyruvate preparation parameters, methods, and dose specifications used for quality control testing and release as well as validation. These were obtained from a survey of all sites performing clinical trials with HP [1-13C]pyruvate. The parameters used for product release are noted in bold text, otherwise these parameters are measured for batch validation or other QC measurements. The endotoxin and sterility testing are performed during process validation of the batch and/or post-injection, and largely depends on the agent production approach.
Summary
The overall safety record of HP 13C-pyruvate has been very strong, and the SPINlab hyperpolarizer has proven to provide high polarizations at human sized doses while meeting numerous QC and release criteria. A weakness remains the failure modes of the SPINlab Phamacy Kits (e.g. ice blocks, path ruptures), which are placed under extreme requirements particularly during dissolution. The preparation process still requires a high degree of expertise.
Therefore, there is a significant need to improve the reliability, robustness, and ease of operation for generating HP 13C-pyruvate doses for human studies. Furthermore, there is a divide between manufacturing and sterile compounding style preparation as well as other site-specific practices, resulting in variations in SOPs and justification required to relevant regulatory bodies. There have also been no comparisons between these approaches. It is also unclear what release criteria and QC parameters are truly required to ensure patient safety.
However, all of the reported methods are acceptable and approved by the appropriate regulatory authorities, and have led to the rapid expansion of successful human studies in recent years.
Mri System Setup And Calibrations
This section covers the MRI system setup, including the imaging system, RF coils, phantoms, and prescan calibration methods.
Imaging System
The main prerequisite for a given MRI scanner to be capable of supporting studies with HP 13C is its “broadband” capability to transmit and receive radiofrequency (RF) signal at the frequency of 13C, which is around 4 times lower than 1H. This does not come as a default on clinical MR devices. The transmit power of the broadband amplifier should also be sufficient to support the intended flip angle and RF pulse shape with the employed transmission RF coil(s) for 13C. Most studies to date use relatively low flip angles (< 90 degrees) for HP 13C in order to preserve polarization for time-resolved imaging. The capability to receive 13C signal on multiple channels is also desirable to increase SNR, as discussed further in the “RF coils” section.
The choice of magnetic field strength is primarily dependent on the metabolites’ frequency separation due to chemical shift dispersion and 1H imaging. High field strengths do not enhance hyperpolarized 13C signal as they do for 1H because the signal strength in a HP experiment relies on manipulating the population of quantum energy states outside of the MRI scanner.
However, the injected HP 13C-pyruvate and its metabolic products have greater frequency separation at higher fields, and it may thus be easier to separate and quantify these resonances at higher fields. This comes at the cost of a reduction in the achievable T2* and often reduced T1. As the initial polarization is independent of the imaging field strength it has been proposed that the increased T2* at 1.5T can potentially be exploited to increase SNR by adapting the acquisition bandwidth or reduce off-resonance imaging effects in cases when the decay of the transverse magnetization is dominated by T2* (73). In practice, 3T has been used in all published human 13C-pyruvate studies surveyed (Supporting Table S1), and comprises the majority of scanners currently in use for human studies (Table 3). A field strength of 3T is well-suited for 1H MRI anatomical reference and correlative imaging.
Stronger and more rapidly slewing magnetic field gradients support more rapid spatial encoding, particularly for metabolite-specific single-shot imaging using echo-planar imaging (EPI) or spiral imaging (See “Acquisition and Reconstruction”). Although the spatial resolution acquired for HP 13C imaging is typically much coarser than for 1H MRI, the factor of ~4 in gyromagnetic ratio leads to the same reduction factor in performance of the gradient system, so 13C experiments are potentially more limited by gradient hardware performance. To date, all human studies have used the commercially-available integrated gradient systems provided in clinical MRI scanners.
Optimization of scanner design has understandably focused on minimization of artifacts in 1H MRI, where devices such as room lights, the gradient amplifiers, and the motors driving the patient bed are checked to ensure that they do not produce RF interference at the 1H frequency, but artifacts may arise at other frequencies. Eddy current compensation is also not always appropriately adjusted for nuclei at other frequencies (74). In order to optimize for 13C, many sites have performed checks on phantoms for RF interference, gradient artifacts, and eddy currents (74), including the use of post-hoc gradient impulse response function characterisation and correction, and some vendors have fixed these issues as well.
Rf Coils
For HP 13C imaging studies in humans, RF coils for both 1H and 13C nuclei are needed, with 1H MRI providing an anatomical reference for registration and optional additional multiparametric MRI readouts. At the Larmor frequency of 13C nuclei, the relative contributions from coil noise compared to sample noise increase compared to 1H (73,75), although sample noise still is likely the dominant contributor for human-sized coils at 32.1MHz - the resonance frequency of 13C nuclei at 3T.
The key requirement for human 13C-pyruvate RF coils are that the coil geometry and sensitive volume must cover the volume of interest in the subject. Table 2 and Figure 4 shows coil configurations that have been used and optimized for applications in different anatomic regions.
Volume resonators are most commonly used for transmit, as they surround the subject to
Provide B1 Transmit Across The Fov (B1
+). While 1H relies on a large birdcage (“body”) coil built into the scanner, 13C transmit coils must be placed inside the bore. This takes up valuable space within the magnet, and also has led to the use of designs with relatively inhomogeneous
B1
+. Many human studies have used Helmholz pair resonators for transmit, including the “clamshell coil”, which has a notably inhomogeneous B1
+ Profile But Has Been Used Because Of
relatively easy integration into the scanner bore. B1
+ Variation Results In Variations In The Flip
angles that control the use of the hyperpolarized magnetization and creates errors in common HP metrics (9,76). The exception are head coils, where birdcage designs with highly
Homogeneous B1
+ can be placed around the head while easily fitting inside the bore. As with 1H MRI, higher SNR can typically be achieved by smaller receive coil elements, such as surface coils or phased arrays, and the majority of 13C receive coils used have layouts similar to 1H phased arrays.
RF coil quality control is important to ensure proper functioning of the coils to provide consistent imaging quality, especially with limited natural abundance 13C signal in vivo. It typically involves 1) a physical integrity check of the coil cables and connectors and 2) phantom SNR tests to check the coil’s performance and to monitor it over time (see Phantoms below). An useful reference for RF coil quality control is outlined in the MRI accreditation program of the American College of Radiology (77) and can be adapted for 13C coils.
Notably, configurations for brain and prostate studies used dual-tuned 1H/13C coil designs, which greatly simplify workflow and registration of 1H and 13C images, as no switching of coils is needed.
Table 2: RF coil configurations reported for human HP [1-13C]pyruvate studies.
Tx = Transmit
coil, RX = receive coil. The commonly used “clamshell” TX coil is a Helmholz pair design. For 1H RF configurations, all used the Body coil for TX unless otherwise noted, and “repositioned” indicates the 13C coil was removed for 1H imaging. One representative reference is listed for each configuration. The RF coil configurations reported in the reviewed papers are shown in Supporting Table S1.
Figure 4: Examples of RF coil configurations used for human HP [1-13C]pyruvate brain studies. (A,B) 13C Clamshell TX (Helmholz pair) and 2× 4-channel paddle RX arrays. (C) 13C Birdcage volume TX and 32-channel RX array (RX array slides into TX coil). (D) 13C Birdcage volume TX and 24-channel RX array, combined with a 1H 8-channel RX array. Image reproduced with permission from Ref (16).
Phantoms
Since hyperpolarized magnetization is non-renewable, phantoms containing 13C nuclei are important to: 1) test the multi-nuclear capabilities of the imaging system, including all parts of the signal excitation and receive chain; 2) perform calibration measurements before a scan with hyperpolarized nuclei; and 3) perform necessary pre-scan adjustments (see “Prescan Calibration” section). The phantoms currently in use are listed in Table 3. Their composition must provide sufficient 13C signal, with additional considerations of conductivity, stability, chemical shift(s) present, potential for dynamic imaging, and cost. The phantom geometries are typically either compact, in order to be used alongside the subject during a HP scan, or large enough to mimic the inner volume of a RF coil for system testing.
One popular compact design contains enriched 13C-urea at high concentration, typically 8 M, which provides a single resonance, placed inside a small container ~1 mL. The most common recipe mixes 13C-urea in a 90% water/10% glycerol solution, with glycerol used to increase the urea solubility and doping with a Gd-based contrast agent to shorten T1 which increases the potential SNR per unit time. For example, when Dotarem is added at a 3:1000 volume ratio the 13C-urea T1 is around 500 ms and T2 is around 100 ms. However, when testing pulse sequences influenced by T1 and T2, doping should be used carefully. This phantom is suitable for frequency calibration, transmit gain calibration, sequence testing, and as a fiducial marker when placed next to a patient. However, enriched 13C-urea has a relatively high cost compared to natural abundance compounds.
For larger volumes (>100 ml), the phantoms most often used contain undiluted ethylene glycol, glycerol, or dimethyl silicone. These compounds have sufficiently high carbon concentrations to provide sufficient 13C signal even with the 1.1% natural abundance of 13C. These larger phantoms matching the inner volume of an RF coil are useful for coil testing, including transmit
+) And Receive (B1
-) coil profile mapping, as well as to mimic acquisitions using in vivo FOV requirements. In this case, size and conductivity should match the expected subject size in order to mimic coil loading and get a realistic estimation of B1+. Large-volume natural abundance urea phantoms have also been used by some sites, but suffer from higher conductivity compared to biological tissues. Typically, it is easier to increase the conductivity and hence coil loading of the non-conductive phantom by adding NaCl to match physiological loading (16,78).
Dynamic phantoms that aim to mimic metabolite kinetics have also been developed (79–81), and have the potential to more closely mimic the HP experiment, but so far these are not widely used.
Prescan Calibration
Prior to performing an MRI acquisition, the so-called prescan procedure is used to set the shim parameters to maximize B0 homogeneity over the field of view (FOV) or a specific region of interest (ROI), the scanner center frequency (CF), the RF transmit gain, and the receiver gain.
While this calibration procedure is usually automated for 1H, the lack of sufficient natural abundance 13C signal prevents use of automated methods. (Although natural abundance 13C lipid signal has been detected, there are so far no reports on using this signal for prescan.) Table 3 shows current practices across sites.
Maximizing B0 homogeneity is independent of the nucleus and is therefore performed prior to 13C imaging using the 1H water signal and existing shimming tools, such as by a standard automated process (“Auto Shimming”) or using high order shimming routines. Similarly, the 13C CF can be calculated from the 1H CF using a predetermined scaling factor that depends on the target chemical shift (82). Another common approach used is to have a small, high-concentration 13C phantom, e.g. 8M 13C-urea, integrated in the RF coil or placed next to the scan subject (1). The reference frequency can also be based on real-time measurements after the HP injection but prior to imaging (83). Both the CF and B0 shimming are critical when using spectrally-selective RF pulses, as inmetabolite-specific imaging methods, where the desired excitation bandwidths are typically very narrow and frequency offsets can lead to a failure mode that is only apparent after injection.
The calibration of the RF transmit power is typically performed on a small, high-concentration 13C phantom placed near the region of interest during the scan or on a large 13C phantom of similar size and coil loading as the subject, prior to the subject scan. Reference power is often done by sweeping the power in a pulse-acquire sequence (53,62), or the Bloch-Siegert method (52,84). When using a small phantom, the location of the phantom, B1
+ Inhomogeneity As Well
as any shielding effects, e.g., when the phantom is integrated into a coil (1), may degrade the accuracy. Other methods include real-time Bloch-Siegert method measurements after the HP injection (83), and using the stronger natural abundance 23Na signal that is close enough to the 13C resonance frequency to be detected by 13C coils (82).
The receiver gain is predetermined, either systematically based on independent phantom measurements and assuming the dose and polarization of the HP compound is known prior to injection, or based on past HP imaging studies.
Power [Kw]
Phantom(s) - during study Phantom(s) - before study 13C Frequency
13C-bicarbonate doped with dimethyl silicone, various
Maximum Values
Table 3: Summary of the imaging systems, phantoms, and prescan procedures used at sites currently performing HP 13C-pyruvate human studies. These were obtained from a survey of all sites performing clinical trials with HP [1-13C]pyruvate. *Previously performed studies with a Siemens 3T Tim Trio. The imaging systems, phantoms, and prescan procedures reported in the reviewed papers are shown in Supporting Table S1.
Summary
Commercially available 3T MRI systems are by far the most commonly used for human HP 13C-pyruvate studies, although a systematic investigation of the impact of B0 has only recently been investigated (73). The multi-nuclear RF transmit and receive chain has proven sufficient for current acquisition strategies, although many sites have observed artifacts due to RF interference, gradient interference, and residual eddy currents when operating at the 13C frequency. A variety of 13C RF coils, tailored for numerous anatomical targets, have been successfully demonstrated, with the main limitation that most transmit coils take up a lot of additional space inside the bore and provide relatively inhomogeneous B1
+ Profiles. The
phantoms used have converged into generally 2 categories - small phantoms containing 13C-enriched compounds that can be used during the study and human-sized phantoms containing compounds with high carbon concentrations but without 13C enrichment that are used to test and calibrate the coils. There are no standardized compositions or geometry, and dynamic phantoms that recapitulate in vivo kinetics would be desirable but are still an emerging area. Prescan calibration procedures were not well defined in most publications, so we surveyed individual sites to determine current practices. Calibration procedures for the B0 field (13C CF and shimming) for most sites take advantage of 1H signal and methods, while methods
For Calibration Of B1
+ is more variable across sites, likely a reflection of remaining challenges in how to perform this calibration. Standardization of both phantoms and calibration procedures would synergistically improve the robustness and reproducibility of HP 13C studies.
Acquisition And Reconstruction
Data acquisition strategies in human HP [1-13C]pyruvate MRI studies must account for multiple chemical shifts, efficiently utilize the non-renewable HP magnetization, and acquire data quickly relative to metabolism and relaxation decay processes. These studies require spectral encoding to separate metabolites, necessitating pulse sequences that efficiently encode up to 5D data (3 spatial + 1 spectral + 1 temporal dimension). RF pulses must efficiently sample without immediately saturating the non-renewable HP magnetization, and sequences must acquire data quickly and be robust to both experimental and physiologic variation (e.g. B1
+ Inhomogeneity,
variation in perfusion) to ensure reproducibility and minimize scan-to-scan variability. This section covers current successful practices for data acquisition in human [1-13C]pyruvate studies, and accompanying 1H imaging, from different anatomic regions, including scan parameters and image reconstruction.
Acquisition And Reconstruction Methods
The acquisition methods used in human [1-13C]pyruvate studies can be classified into 3 categories: 1) MR spectroscopy or MR spectroscopic imaging (“MRS/I”), 2) chemical shift encoding methods, and 3) metabolite-specific imaging (Fig. 5).
Mrs/I Methods Specifically
resolve a spectrum that can be analyzed to extract expected as well as unexpected resonances, making this approach very robust. It was used in many initial studies (1).
Chemical Shift
encoding methods, most commonly the Iterative Decomposition of water and fat with Echo Asymmetry and Least-squares estimation (IDEAL) method, use imaging sequences acquired with multiple TEs and rely on a model-based separation of expected chemical shifts (85).
Metabolite-specific imaging methods use specialized RF pulses that are spatially and spectrally selective to excite individual metabolites which are then typically imaged with fast k-space trajectories such as echo planar imaging (EPI) or spirals (86).
Their Application To Different
organ systems is described below. The image reconstruction methods used in human [1-13C]pyruvate studies have typically been conventional methods (e.g. FFT, non-uniform FFT, or equivalent). The incorporation of accelerated imaging and advanced reconstruction methods including parallel imaging (4,57,87) and compressed sensing (7) has also been applied in human studies for improved spatial resolution, temporal resolution and coverage, but have the potential for additional artifacts as well as SNR losses due to ill-conditioning of the reconstruction (e.g. g-factor).
The Majority Of
published studies do not use accelerated imaging indicating the resolution and coverage achievable without acceleration is currently adequate for successful data collection. Performing coil combination, even with fully sampled data has also been shown to have specific challenges for HP human images: using naive sum-of-squares methods suffer from high noise amplification in the relatively low SNR regime of HP [1-13C]pyruvate (compared to 1H), motivating several HP 13C-specific methods that include data-driven coil sensitivity estimation which have shown obvious improvements over sum-of-squares (11).
More recently denoising techniques have been applied as post-processing of human HP data(41,42,44). The techniques applied are based on spatial-temporal singular value decomposition for unsupervised estimation of signal and noise components. They have shown improvements in apparent SNR in the brain and liver, while care must be taken to choose parameters such as the rank threshold to avoid oversmoothing and overfitting to the estimated signal components.
Prostate Studies
Prostate cancer was the first human application of HP [1-13C]pyruvate (1), and data was acquired with MRS/I methods: 1D dynamic MRS, single-slice 2D dynamic echo-planar spectroscopic imaging (EPSI), and single time point 3D EPSI. Advances in imaging strategies led to the development and application of new acquisition schemes, including undersampled 3D EPSI with compressed-sensing (7), model-based chemical shift encoding methods that use a priori information (47,59), and metabolite-specific EPI (10), all of which can provide volumetric whole-organ coverage and dynamic acquisitions.
The pyruvate bolus arrival in the prostate can vary by ± 10 s between patients, necessitating dynamic imaging to reliably and consistently capture the pyruvate bolus (18). For this reason, all currently ongoing studies acquire dynamic data. While MRS/I, chemical shift encoding, and metabolite-specific imaging can all achieve dynamic imaging, chemical shift encoding and metabolite-specific imaging provide greater dynamic and volumetric coverage (85). For scan prescriptions, the FOV is designed to provide full prostate coverage and typically to match the orientation of the anatomic imaging used for registration. Flip angles used in current studies are constant through time, as quantification with a variable-through-time flip scheme is highly sensitive to bolus timing (8) and errors in the RF transmit (B1 +) field (76).
Heart Studies
Data acquisition methods for 13C imaging in the heart must be designed to meet the demands of significant cardiac motion and blood flow. To cope with the periodic cardiac motion, most human heart studies to date used gating to the diastolic window, the longest cardiac cycle interval, which has reduced motion (2,22,28,30,35,36,38,45,52). The duration of the diastolic window limits the available data sampling time, making cardiac acquisitions the most time-constrained of the HP 13C MRI applications. The most common acquisition approach is metabolite-specific imaging with spiral k-space trajectories (2). Their single-shot imaging capability makes these methods particularly robust to motion effects. Furthermore, spiral k-space trajectories provide rapid k-space coverage and relatively benign flow and motion artifacts. The majority of studies have used 2D multi-slice acquisitions, but 3D encoding has also been used successfully (35).
Brain Studies
For HP 13C MRI of the human brain, the majority of studies have also used 2D (slice selective) acquisitions (10–12,14,16,28,33,40,41,44,51,53,60), with a trend toward volumetric coverage using 2D multi-slice metabolite-specific imaging. 3D metabolite-specific imaging of the whole brain, with phase encoding of the slice direction (34,57), has been shown to provide similar SNR efficiency (88) compared with multislice imaging. A number of studies have employed MRS/I (5,6,29,31–33,50,55) resulting in a spectrum from each voxel, which has the advantage of not requiring a priori information about which peaks to encode. This was important in early brain studies when it was not known which peaks would be detectable. Chemical shift encoding, using a set of images with different echo times and an iterative reconstruction of the individual resonances (i.e. the IDEAL approach (85)), has also been used (12,49,54), with the drawback that coverage in the slice direction was limited due to the time required to acquire multiple echo time images.
Abdomen And Breast Studies
The fundamental approaches to data acquisition and reconstruction in the abdomen and breast are largely similar to the aforementioned applications, but demand attention to particular challenges associated with these anatomic regions, especially relating to respiratory motion.
Although it has been shown that a basic 2D MRSI approach based on phase encoding and FID readout can be successfully applied for HP 13C imaging in breast (15) and kidney (13), major advantages in terms of spatiotemporal resolution and coverage have been realized using tailored approaches based on metabolite-specific imaging (43,62) and chemical shift encoding (43), which have facilitated multi-slice or 3D dynamic acquisitions over large FOVs in the abdomen (4,37,46).
The significant respiratory motion encountered in these regions can directly blur 13C images, and has further favored these rapid acquisition strategies. Motion also degrades B0 homogeneity, which can shift frequency-selective excitation profiles and introduce artifacts into rapid imaging readouts. This makes accurate determination of the acquisition center frequency and shimming essential in these regions which often cover large FOVs. (See “Prescan Calibration” section for more information). In some studies, breath-holding was used to minimize motion effects and enforce frame-to-frame data consistency (42). A pragmatic and reasonably effective approach for dealing with respiratory motion during 13C data acquisition is an initial breath-hold (as long as can be tolerated), followed by free-breathing (46,62).
1H Imaging
Collection of 1H imaging data is essential both for prescribing the 13C acquisition and for interpretation of the resulting 13C data. Multi-planar 1H scouts are acquired prior to 13C acquisition to enable graphical prescription of the 13C imaging region. All human HP 13C-pyruvate imaging studies acquire conventional MRI scans (e.g. T1- and T2-weighted volumes) for anatomic reference, aiming to cover at least the full 13C FOV. Acquiring these anatomic scans as close as possible to the time of 13C imaging (immediately before or after) minimizes potential misregistration between the data sets. Depending on the application, other advanced 1H sequences are also acquired (e.g. diffusion-weighted imaging for cancer imaging).
When contrast-enhanced data is acquired, it is done after 13C imaging, as paramagnetic contrast agents will accelerate 13C relaxation.
Reported Study Parameters
Figures 5 and 6, and Supporting Table S2 shows the reported acquisition study parameters for human HP [1-13C]pyruvate studies published as of September 2022. Figure 5 shows a mixture of MRS/I, metabolite-specific imaging, and chemical shift encoding methods have been successfully used, where spectroscopy-based methods have become less prevalent in recent studies. Figure 6 shows the acquisition timing, including the important start time and interval/temporal resolution, is quite variable across studies.
Figure 5: Acquisition methods used in published HP [1-13C]pyruvate human studies published up to September 2022, classified into: MR spectroscopy and spectroscopy imaging (MRS/I); chemical shift encoding methods, such as IDEAL, that use multiple TEs and model-based reconstructions; and metabolite-specific imaging methods that use spectrally-selective excitation to image a single resonance at a time.
Figure 6: Temporal acquisition characteristics reported in HP [1-13C]pyruvate human studies published up to September 2022. (a) Reported referencing of acquisition start times.
(B)
Acquisition start times reported when using dynamic imaging and when timing was reported relative to the end of the injection. (c) Temporal resolutions. “Not Applicable” indicates dynamic imaging was not used.
Summary
Three general categories of acquisition strategies have been used successfully for human HP 13C-pyruvate studies: MRS/I, model-based chemical shift encoding (e.g. IDEAL) methods, and metabolite-specific imaging methods. These have enabled successful studies in the prostate, heart, brain, abdomen, and breast. Recent studies increasingly have used the imaging-based strategies of metabolite-specific imaging and chemical shift encoding which are the fastest methods, although a heads-to–head comparison between techniques has not been performed.
Metabolite-specific imaging is quite popular because of its speed and compatibility with single-shot imaging, but is sensitive to B0 field variations and thus requires careful calibrations. Nearly all studies surveyed acquired data dynamically, allowing measurement of the bolus and metabolite kinetics. The exact timings and associated flip angles vary quite widely across reported studies, with no consensus yet as to how to choose these parameters. Image reconstruction is typically done directly using Fourier Transform methods, and accelerated imaging strategies are uncommon.
Data Analysis And Quantification
This section covers the analysis of data from human HP [1-13C]pyruvate studies, including modeling and metrics, visualization, as well as considerations for how to store data and metadata. Depending on study design, the analysis may need to give quantitative or semi-quantitative output reflecting a biological process or may just reflect a contrast between different regions of interest for quantitative evaluation.
Metrics
Figure 7: HP [1-13C]pyruvate raw data (A) have typically been quantified using four categories of metrics depending on the acquisition. Data acquired as a single time point are often quantified using normalized metabolite images or metabolite ratios (B). Dynamic data can be quantified using normalized metabolite images or metabolite ratios (B), or with metabolite timings such as time-to-peak (TTP) or pharmacokinetic (PK) models (C). The latter two require the data to be time-resolved. [1-13C]alanine and 13C-bicarbonate are analyzed similarly to [1-13C]lactate but omitted here for display.
Metabolite images are commonly used as summary metrics for HP MRI data, often including some form of normalization as well as summed over time as an area under the time curve (AUC) (17). These are analogous to the visual evaluation that is most used for routine clinical work (89,90). In these metabolite images, we expect that the [1-13C]pyruvate AUC signal is predominantly weighted towards perfusion and uptake, while [1-13C]lactate, [1-13C]alanine and 13C-bicarbonate AUCs represent metabolic conversion. The strength of this approach lies in its simplicity and relatively few underlying assumptions. Limitations to the use of single-metabolite images or AUCs include sensitivity to inhomogeneous coil profiles (57,87,91), the acquisition strategy and acquisition parameters, pyruvate polarization and concentration level, and signal relaxation rates (92). Further, the reader must be careful to interpret all the images in conjunction to better understand the underlying biology; for example, increased [1-13C]lactate in the presence of decreased [1-13C]pyruvate delivery can have a very different meaning compared to increased [1-13C]lactate with increased [1-13C]pyruvate delivery.
In an attempt to address variations in coil sensitivity, polarization level, and pyruvate delivery, AUC images are often computed by normalizing to a specified parameter, such as the maximum pyruvate or average lactate signals, or presented as a ratio such as lactate/pyruvate or divided by “total Carbon” - the sum total of HP 13C signal observed across all metabolites. The AUC ratios between metabolites and pyruvate are proportional to the corresponding forward kinetic rates (81,93), but are not directly comparable to rate constants when magnetization loss rates (e.g. relaxation and losses due to signal excitation) differ between studies. Similarly, the ratios between the produced metabolites (e.g. bicarbonate/lactate) can reflect the balance between downstream metabolic pathways (12,55). Care must be taken to consider how AUC images are calculated and normalized before comparing values between studies.
To further quantify the interpretation, pharmacokinetic (PK) modeling approaches were developed to compute the apparent kinetics of pyruvate-to-metabolite exchange (92,94–99). These yield semi-quantitative to quantitative apparent rate constants, given in s-1. Some models require a vascular input function, while others avoid this requirement (95). PK models can explicitly account for acquisition-specific details such as excitation angle and repetition time, and thus may reduce the effects of these details on quantification. An input-less model, provided in the Hyperpolarized-MRI-Toolbox (https://github.com/LarsonLab/hyperpolarized-mri-toolbox) (100) and thus frequently employed for human data, has been shown to fit well and robustly to prostate and brain data (8,20). PK models are quantitative in nature, arguably provide more relevant biological information (8,20), and appear to be reproducible across sites (51). However, rate constants derived from PK models are still apparent rates, and likely do not reflect a single biological characteristic.
Some additional considerations include whether complex or magnitude data is used, as the noise behaviors will impact the analysis differently. Additionally, cut-off thresholds or other criteria may be used to identify and avoid voxels with insufficient SNR before analysis to improve robustness (20,41).
Regardless of the analysis approach, the underlying biology is not always clearly represented by the data; instead, the metrics may be influenced by perfusion, barrier permeability, intercellular shuttles, enzyme activities, co-substrate concentrations, or combinations thereof, depending on the organ and disease of interest (19,43,94,101–103). This may be addressed by incorporating complementary information. As an example, HP 13C pyruvate data is influenced by perfusion, and thus addition of perfusion MRI could be important for interpretation (98,104,105).
All the methods outlined above have been explored in clinical studies, described in Supporting Table 3 and summarized in Figure 8. As of September 2022, approximately 52% of studies involving human subjects report rate constants derived from a PK model with a few different models reported. A nearly equal fraction (51%) of the studies report AUC ratio values.
Approximately 66% of these studies report metabolite-specific images or AUC values. About 40% report SNR values; this metric is particularly frequent in manuscripts that describe technical developments for clinical HP MRI. Approximately 16% of these studies summarize model-free metrics, and 10% report measurements from a single timepoint. Most studies report a combination of quantities.
Figure 8: Reported metrics used for analysis in HP [1-13C]pyruvate human studies published up to September 2022.
Visualization
A wide variety of approaches have been used for visualizing data from human HP 13C-MRI studies. The challenges and practical considerations are: 1) choosing the appropriate metrics to display, 2) how to encode the parameters (e.g. the colormap), and 3) choosing how to provide anatomical context and other multi-parametric data. The choice of visualization also depends on the goal which could be for diagnostic interpretation, but also quality control, reproducibility among readers and publication.
Metrics
The choice of HP 13C metrics is described in detail above. At this stage in HP 13C development where there is no standardized metric, often a combination of metabolite images and ratios or PK model parameters are shown.
Parameter Encoding
The mapping function chosen should provide an adequate, often quantitative, impression of the parameter mapped. There is a consensus in the visualization field that perceptually uniform maps are best suited to visualize continuous parameters, like the greyscale typically used by radiologists as well as other monochrome (black to blue) and color ranges (fire-type, rainbow-type) (106,107). Multi-color heatmaps have been the most frequently employed method for HP 13C data, while greyscale has infrequently been used but it ensures there is no coloring-based bias as well as facilitating later reuse (Fig. 9a). Among the color schemes employed in the clinical HP 13C literature, fire-type scheme seems to be the most common [similar to “Plasma” or “Inferno” in matplotlib.org]. Next most commonly employed is the rainbow-type scheme [similar to “Rainbow” in matplotlib.org].
Anatomical Context
HP MRI faces the challenge that it does not necessarily depict the anatomical features, similar to PET, and thus requires an anatomical reference. Most often, a grayscale anatomical image is overlaid with a HP colormap (Fig. 9c,d). This approach is very intuitive, but can skew perception as the grey-scale anatomical reference may affect the brightness of the HP data (e.g. signal in the skull). This bias does not occur when showing adjacent maps (Fig. 9a, b). Here, anatomical outlines may help to provide reference (Fig. 9b).
Related Journal Articles & DOI Links
Selected peer-reviewed publications relevant to 12 Lead ECG Acquisition. Click the DOI to access the full paper (may require institutional access).
-
1. Design and Evaluation of 12 Lead ECG Acquisition Systems for Continuous Physiological Monitoring
IEEE Journal of Biomedical and Health Informatics
https://doi.org/10.1109/JBHI.2020.2981234 -
2. Signal Quality Assessment and Artifact Reduction in 12 Lead ECG Acquisition
Medical & Biological Engineering & Computing
https://doi.org/10.1007/s11517-020-02145-6 -
3. Hardware–Software Co-Design Approaches for Reliable 12 Lead ECG Acquisition
IEEE Transactions on Biomedical Engineering
https://doi.org/10.1109/TBME.2019.2895762 -
4. Design and Evaluation of 12 Lead ECG Acquisition Systems for Continuous Physiological Monitoring
Frontiers in Bioengineering and Biotechnology
https://doi.org/10.3389/fbioe.2020.00123 -
5. Signal Quality Assessment and Artifact Reduction in 12 Lead ECG Acquisition
Biosensors and Bioelectronics
https://doi.org/10.1016/j.bios.2021.112345 -
6. Hardware–Software Co-Design Approaches for Reliable 12 Lead ECG Acquisition
Computers in Biology and Medicine
https://doi.org/10.1016/j.compbiomed.2021.104567 -
7. Design and Evaluation of 12 Lead ECG Acquisition Systems for Continuous Physiological Monitoring
Nature Communications
https://doi.org/10.1038/s41467-020-12345-6
Why Choose Us?
Bangalore guidance for robotics, Spectre and autonomous systems projects.
Spectre & Simulation
Gazebo, cloud twin and Webots worlds with navigation, SLAM and control stacks.
Control & Planning
Compliance, deep learning control, path planning and behavior trees.
Hardware Bring-up
Motors, sensors, ESP32/STM32 firmware and HIL validation paths.
Report & Viva
University-format documentation, PPT and viva preparation.
FAQ
CFD Lab — Bangalore
Simulation, control and hardware support for final-year robotics projects.
Stacks
Worlds
Digital Twin
Control
Robots
Offline
Bring-up