arXiv:2506.00660cs.LGcs.AI2025-06被引 30

医疗AI用差分隐私保护数据,但可能牺牲模型准确性和公平性

Differential privacy for medical deep learning: methods, tradeoffs, and deployment implications

  • 采用差分隐私训练医疗深度学习模型,权衡隐私与性能
  • 强隐私保护下图像任务性能尚可,复杂或小样本数据损失严重
  • 隐私机制对少数群体影响更大,多数研究未评估公平性

差分隐私(DP)是保护医疗深度学习中敏感患者数据的关键技术。随着临床模型日益依赖数据,如何在隐私、性能与公平性之间取得平衡成为关键挑战。本综述系统梳理了截至2025年3月的74项相关研究,聚焦集中式与联邦设置下的DP-SGD及其他机制。分析涵盖多种数据模态、训练方式与下游任务,揭示隐私保障、模型准确率及子群体公平性之间的权衡。结果表明,强隐私预算下,结构良好影像任务性能仍可保持;但在严格隐私约束下,尤其在代表性不足或复杂模态中,性能显著下降。此外,隐私带来的性能差距对特定人口子群影响更显著,公平性影响因数据类型和任务而异。仅有少数研究通过子群分析或公平性指标关注此问题,多数完全忽略。除DP-SGD外,新兴方法包括替代机制、生成模型与混合联邦设计,但报告不一致。最后,本文指出了公平性审计、标准化与评估协议方面的关键缺口,为构建公平且临床可靠的隐私保护医疗深度学习系统提供方向。

原文摘要 · Abstract (English)

Differential privacy (DP) is a key technique for protecting sensitive patient data in medical deep learning (DL). As clinical models grow more data-dependent, balancing privacy with utility and fairness has become a critical challenge. This scoping review synthesizes recent developments in applying DP to medical DL, with a particular focus on DP-SGD and alternative mechanisms across centralized and federated settings. Using a structured search strategy, we identified 74 studies published up to March 2025. Our analysis spans diverse data modalities, training setups, and downstream tasks, and highlights the tradeoffs between privacy guarantees, model accuracy, and subgroup fairness. We find that while DP-especially at strong privacy budgets-can preserve performance in well-structured imaging tasks, severe degradation often occurs under strict privacy, particularly in underrepresented or complex modalities. Furthermore, privacy-induced performance gaps disproportionately affect demographic subgroups, with fairness impacts varying by data type and task. A small subset of studies explicitly addresses these tradeoffs through subgroup analysis or fairness metrics, but most omit them entirely. Beyond DP-SGD, emerging approaches leverage alternative mechanisms, generative models, and hybrid federated designs, though reporting remains inconsistent. We conclude by outlining key gaps in fairness auditing, standardization, and evaluation protocols, offering guidance for future work toward equitable and clinically robust privacy-preserving DL systems in medicine.

差分隐私医疗AI公平性联邦学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。