为医疗语音隐私保护设计攻击者与防护者模型,兼顾安全与诊断可用性
Scenario of Use Scheme: Threat Model Specification for Speaker Privacy Protection in the Medical Domain
- 提出攻击者-防护者双模型框架,明确医疗语音保护的使用场景
- 在保护性别信息不被推断的同时,保持帕金森病检测准确率90%以上
- 适合医疗AI研发人员和隐私保护方案设计者参考
语音记录正越来越多地用于疾病检测与监测,引发隐私担忧。除加密外,可通过扰动、解耦和重合成等方法消除说话人敏感信息,同时保留对医学分析有用的内容。为发展此类隐私保护技术,需明确医疗场景假设及医务人员需求。本文提出一种使用场景方案,包含攻击者模型(描述需防御的对手)和防护者模型(定义防御机制)。探讨该方案与以往语音隐私研究的关联,并给出具体实例:在抵御性别推断攻击的同时,维持帕金森病检测的实用性。实验表明,该方法可在保证90%以上检测准确率前提下有效隐藏性别信息。
原文摘要 · Abstract (English)
Speech recordings are being more frequently used to detect and monitor disease, leading to privacy concerns. Beyond cryptography, protection of speech can be addressed by approaches, such as perturbation, disentanglement, and re-synthesis, that eliminate sensitive information of the speaker, leaving the information necessary for medical analysis purposes. In order for such privacy protective approaches to be developed, clear and systematic specifications of assumptions concerning medical settings and the needs of medical professionals are necessary. In this paper, we propose a Scenario of Use Scheme that incorporates an Attacker Model, which characterizes the adversary against whom the speaker's privacy must be defended, and a Protector Model, which specifies the defense. We discuss the connection of the scheme with previous work on speech privacy. Finally, we present a concrete example of a specified Scenario of Use and a set of experiments about protecting speaker data against gender inference attacks while maintaining utility for Parkinson's detection.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。