arXiv:2601.10004cs.CRcs.LG2026-01被引 3

剖析医疗大模型全链条隐私风险,给出针对性防护建议

SoK: Privacy-aware LLM in Healthcare: Threat Model, Privacy Techniques, Challenges and Recommendations

  • 构建医疗大模型三阶段威胁模型:数据预处理、微调、推理
  • 发现现有隐私技术在不同部署环境仍存漏洞,难以全覆盖
  • 适合医疗AI安全研究者与临床系统设计者参考

大语言模型(LLMs)正被广泛用于支持临床决策、总结电子健康记录(EHR)和提升患者护理。然而,这一融合带来了显著的隐私与安全挑战,源于临床数据的敏感性及医疗工作流的高风险性。这些风险在从本地医院系统到区域医疗网络的异构部署环境中尤为突出,各环境资源限制与监管要求各异。本文系统化知识(SoK)分析了真实医疗场景下大模型三个核心阶段——数据预处理、微调与推理——的演进威胁态势。提出详细的威胁模型,刻画各阶段的攻击者、能力与攻击面,并系统梳理现有隐私保护技术(PPTs)的应对策略。尽管现有防御手段展现出潜力,但我们的分析揭示其在多样操作层级中仍无法有效保障敏感临床数据安全。最后,提出分阶段的改进建议与未来研究方向,旨在增强受监管环境下大模型的隐私保障能力。本工作为理解大模型、威胁与医疗隐私的交叉关系提供了基础,指明了更稳健、可信赖医疗AI的发展路径。

原文摘要 · Abstract (English)

Large Language Models (LLMs) are increasingly adopted in healthcare to support clinical decision-making, summarize electronic health records (EHRs), and enhance patient care. However, this integration introduces significant privacy and security challenges, driven by the sensitivity of clinical data and the high-stakes nature of medical workflows. These risks become even more pronounced across heterogeneous deployment environments, ranging from small on-premise hospital systems to regional health networks, each with unique resource limitations and regulatory demands. This Systematization of Knowledge (SoK) examines the evolving threat landscape across the three core LLM phases: Data preprocessing, Fine-tuning, and Inference within realistic healthcare settings. We present a detailed threat model that characterizes adversaries, capabilities, and attack surfaces at each phase, and we systematize how existing privacy-preserving techniques (PPTs) attempt to mitigate these vulnerabilities. While existing defenses show promise, our analysis identifies persistent limitations in securing sensitive clinical data across diverse operational tiers. We conclude with phase-aware recommendations and future research directions aimed at strengthening privacy guarantees for LLMs in regulated environments. This work provides a foundation for understanding the intersection of LLMs, threats, and privacy in healthcare, offering a roadmap toward more robust and clinically trustworthy AI systems.

医疗AI隐私保护大模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。