保护隐私的医疗影像分割框架,实现多机构协作不泄露数据。
Privacy-Preserving Collaborative Medical Image Segmentation Using Latent Transform Networks
- 用跳连自编码器和密钥化隐空间变换保护共享特征
- 在4个数据集上达最优分割精度,边界误差更低
- 抗图像重构和成员推断攻击,适合医院间安全协作
跨机构协同训练对构建可靠的医学图像分割模型至关重要。然而,隐私法规、数据孤岛和数据分布不均导致医院难以共享原始扫描或标注,限制了可泛化的模型训练。现有的隐空间协作框架(如隐私分割框架SF)虽有潜力,但仍面临分割精度不足及隐空间逆向与成员推断攻击的风险。本文提出一种面向异构医学数据的隐私保护协作分割框架(PPCMI-SF),结合图像与掩码的跳连自编码器,以及客户端特定的正交混洗与置换隐空间变换,在共享前保护隐特征。服务器端统一映射网络执行多尺度隐空间到隐空间转换,实现分割推理而无需暴露原始数据。在四个数据集(PSFH超声、超声神经分割、FUMPE CTA、心脏MRI)上的实验表明,所提方法在Dice分数、HD95和平均对称表面距离(ASD)上均优于现有最先进方法,并达到与无隐私假设基线相当的性能。隐私测试证实其对逆向攻击和成员推断攻击具有强抵抗能力,系统实现实时推理且通信开销低。结果表明,多机构环境下可实现高精度、高效且不泄露隐私的医学图像分割。
原文摘要 · Abstract (English)
Collaborative training across multiple institutions is becoming essential for building reliable medical image segmentation models. However, privacy regulations, data silos, and uneven data availability prevent hospitals from sharing raw scans or annotations, limiting the ability to train generalizable models. Latent-space collaboration frameworks such as privacy-segmentation framework (SF) offer a promising alternative, but such methods still face challenges in segmentation accuracy and vulnerability to latent inversion and membership-inference attacks. This work introduces a privacy-preserving collaborative medical image segmentation framework (PPCMI-SF) designed for heterogeneous medical datasets. The approach combines skip-connected autoencoders for images and masks with a keyed latent transform that applies client-specific orthogonal mixing and permutation to protect latent features before they are shared. A unified mapping network on the server-side performs multi-scale latent-to-latent translation, enabling segmentation inference without exposing raw data. Experiments on four datasets: PSFH ultrasound, ultrasound nerve segmentation, FUMPE CTA, and cardiac MRI show that the proposed PPCMI-SF consistently achieves high Dice scores and improved boundary accuracy, as reflected by lower 95th percentile Hausdorff distance (HD95) and average symmetric surface distance (ASD) compared to the current state-of-the-art and performs competitively with privacy-agnostic baselines. Privacy tests confirm strong resistance to inversion and membership attacks, and the overall system achieves real-time inference with low communication overhead. These results demonstrate that accurate and efficient medical image segmentation can be achieved without compromising data privacy in multi-institution settings.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。