小规模医疗数据训练的生成模型反而更难泄露隐私,适合保护患者信息。
Generative clinical time series models trained on moderate amounts of patient data are privacy preserving
- 用小规模真实数据训练生成模型,能自然隐藏个体信息。
- 在大规模数据上训练的模型生成数据,可抵御常见隐私攻击。
- 差分隐私会降低模型实用性,不推荐用于此类生成模型。
由于患者数据共享可能泄露个人身份信息,医疗数据的机器学习应用常受阻。生成式人工智能(genAI)通过合成数据被视为潜在解决方案。尽管近期已有针对异构医院时间序列的强大生成模型,但其生成数据仍可能暴露训练集中的个体信息。现有隐私保护机制面临挑战:事后匿名化效果有限,而引入差分隐私(DP)可能导致训练不稳定,损害生成数据的可用性。本研究使用多种成熟隐私攻击方法,对基于公开MIMIC-IV数据集训练的先进医院时间序列生成模型进行隐私审计,并利用eICU数据集对MIMIC-IV训练的生成器发起攻击。结果表明,当生成模型在足够大的数据集上训练时,主流隐私攻击无法成功。此外,我们发现将现有差分隐私机制应用于这些生成器无法提升隐私保护,只会降低其在机器学习任务中的性能表现。
原文摘要 · Abstract (English)
Sharing medical data for machine learning model training purposes is often impossible due to the risk of disclosing identifying information about individual patients. Synthetic data produced by generative artificial intelligence (genAI) models trained on real data is often seen as one possible solution to comply with privacy regulations. While powerful genAI models for heterogeneous hospital time series have recently been introduced, such modeling does not guarantee privacy protection, as the generated data may still reveal identifying information about individuals in the models' training cohort. Applying established privacy mechanisms to generative time series models, however, proves challenging as post-hoc data anonymization through k-anonymization or similar techniques is limited, while model-centered privacy mechanisms that implement differential privacy (DP) may lead to unstable training, compromising the utility of generated data. Given these known limitations, privacy audits for generative time series models are currently indispensable regardless of the concrete privacy mechanisms applied to models and/or data. In this work, we use a battery of established privacy attacks to audit state-of-the-art hospital time series models, trained on the public MIMIC-IV dataset, with respect to privacy preservation. Furthermore, the eICU dataset was used to mount a privacy attack against the synthetic data generator trained on the MIMIC-IV dataset. Results show that established privacy attacks are ineffective against generated multivariate clinical time series when synthetic data generators are trained on large enough training datasets. Furthermore, we discuss how the use of existing DP mechanisms for these synthetic data generators would not bring desired improvement in privacy, but only a decrease in utility for machine learning prediction tasks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。