arXiv:2608.07705cs.AIcs.LG2026-08

提出临床大模型隐私风险评估框架,防范模型泄露导致的患者身份识别。

Protecting patient privacy in clinical foundation models: Technical and legal perspectives

论文配图:Protecting patient privacy in clinical foundation models: Technical and legal perspectives
图 1 · 摘自论文原文
  • 构建可落地的隐私风险评估框架,识别模型间接泄露路径。
  • 揭示真实场景下模型泄露可致患者重新识别,超出传统数据控制范围。
  • 结合法律与技术手段,为医疗AI安全部署提供双轨防护方案。

基于大规模患者数据训练的临床基础模型在决策支持、筛查和公共卫生中应用日益广泛。随着部署扩大,模型介导的隐私泄露风险日益凸显,但其普遍性和严重性仍缺乏量化。模型可能暴露敏感训练特征,使患者身份在数据处理控制之外被重新识别。现有框架如HIPAA和GDPR对这类间接威胁指导有限。本文提出实用的隐私风险评估框架,展示不同部署场景下的真实泄露情景,映射至法律体系,并提出互补的技术与法律缓解措施。分析基于真实使用情境,旨在在保障医疗基础模型价值的同时,严格保护患者隐私。

原文摘要 · Abstract (English)

Clinical foundation models trained on large-scale patient data are increasingly used for decision support, screening, and public health. As deployment expands, privacy risk increasingly arises from model-mediated leakage, yet its prevalence and severity remain poorly quantified. Models can disclose sensitive training artifacts, enabling patient re-identification in ways not captured by data-handling controls alone. Existing frameworks, including HIPAA and GDPR, offer limited guidance for such indirect threats. We propose a practical framework for assessing privacy risk in clinical foundation models and illustrate realistic leakage scenarios across deployment settings, map them to legal regimes, and outline complementary technical and legal mitigations. Our analysis provides a context-aware risk assessment grounded in realistic usage to preserve the value of medical foundation models while rigorously safeguarding patient privacy.

隐私保护临床模型AI合规

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。