arXiv:2607.08867cs.CVcs.LG2026-07

评估医学图像伪装技术在隐私保护与模型性能间的平衡

Secure-by-Disguise: A Systematic Evaluation of Image Disguising for Confidential Medical Image Modeling

论文配图:Secure-by-Disguise: A Systematic Evaluation of Image Disguising for Confidential Medical Image Modeling
图 1 · 摘自论文原文
  • 构建统一框架评估多种图像伪装方法的实用性
  • 伪装对分类任务影响小,但严重降低分割精度
  • 医学图像更难被重建,适合隐私敏感场景

基于云的深度学习推动大规模医学图像分析,但将敏感患者图像外包建模带来重大隐私风险。图像伪装作为一种新兴隐私增强技术(PET),可在保持下游学习信息的同时使图像视觉上无法辨识。我们建立统一框架,评估代表性方法DisguisedNets与NeuraCrypt在四个数据集上的表现,涵盖分类与语义分割任务。分析重点包括预测效用、效率及对重建攻击的鲁棒性。结果表明,伪装效果因任务而异:虽能保留分类任务的效用,但在密集语义分割中造成显著性能下降。具体而言,随机多维变换(RMT)在性能与安全间取得最佳平衡,而基于AES的伪装严重损害模型效用。此外,针对自然图像有效的回归重建攻击,在真实医学图像上表现明显较差。研究为保密医疗AI应用中隐私增强技术的选择提供系统性评估。

原文摘要 · Abstract (English)

Cloud-based deep learning enables large-scale medical image analysis but raises significant privacy concerns when sensitive patient images are outsourced for model development. Image disguising has recently emerged as a promising privacy-enhancing technology (PET) that transforms images into visually unintelligible representations while preserving information for downstream learning. We established a unified framework to evaluate representative methods, DisguisedNets and NeuraCrypt, across four datasets involving classification and semantic segmentation tasks. Our analysis assessed predictive utility, efficiency, and robustness against reconstruction attacks. Results showed that image disguising performance varies significantly between tasks; while methods preserved utility for medical image classification, they caused substantial degradation in dense semantic segmentation. Specifically, Randomized Multidimensional Transformation (RMT) offered the optimal balance of performance and security, whereas AES-based disguising severely impacted utility. Furthermore, regression-based reconstruction attacks effective on natural images proved considerably less successful on realistic medical images. These findings provide a systematic assessment of PET suitability for confidential medical AI applications.

医学图像隐私保护图像伪装深度学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。