arXiv:2608.21133cs.CVcs.CR2026-08

提出ClinX框架,用生成式修复解决医疗图文数据隐私泄露问题。

Masking Is Not Enough: Generative Restoration for Multimodal De-Identification in Medical AI

论文配图:Masking Is Not Enough: Generative Restoration for Multimodal De-Identification in Medical AI
图 1 · 摘自论文原文
  • 结合OCR检测与生成式修复,双重抑制图像和文本中的敏感信息。
  • 相比单纯遮盖,生成修复可减少90%以上可恢复的隐私信息。
  • 适合医疗AI训练、评测中需保护患者隐私的研究者使用。

医疗图像-文本数据可能通过可见图像内容及伴随文本暴露受保护健康信息(PHI),尤其在多模态系统中,图像、问题、报告与临床背景均可能进入训练、评估或推理流程,构成隐私风险。现有医学视觉语言基准多关注任务性能,而去标识化方法常独立评估。本文提出ClinX,一个端到端的多模态医疗隐私净化框架。ClinX利用光学字符识别(OCR)检测可见标识,构建二值化隐私掩码,并采用无跳过生成修复模块ClinX-PRISM,配合面向隐私的后处理,实现嵌入式标识的抑制。同时,在文本侧通过渐进式去标识:正则表达式遮盖、上下文感知遮盖、重写式净化降低敏感信息。我们在医学视觉问答(MedVQA)任务上评估ClinX,联合衡量图像侧、文本侧及综合去标识设置下的隐私泄露与下游任务效用。结果表明,仅依赖OCR遮盖不足以应对隐私风险;基于生成修复的净化策略能更好保留临床相关视觉上下文,同时显著降低可恢复的隐私信息。

原文摘要 · Abstract (English)

Medical image-text data can expose protected health information (PHI) through both visible image content as well as accompanying text, creating a barrier to privacy-preserving medical AI systems. This risk is especially prominent in multimodal systems, where images, questions, reports, and clinical context may enter training, evaluation, or inference pipelines. Existing medical vision-language benchmarks primarily emphasize task utility, while de-identification methods are often evaluated separately from downstream reasoning. We introduce ClinX, an end-to-end multimodal PHI sanitization framework for medical image-text data. ClinX detects visible identifiers with optical character recognition (OCR), constructs binary PHI masks, and applies ClinX-PRISM, a no-skip generative restoration module with privacy-oriented post-processing for burned-in identifier suppression. In parallel, text-side PHI is reduced through progressive de-identification levels: regex masking, context-aware masking, and rewrite-based sanitization. We evaluate ClinX in medical visual question answering (MedVQA), jointly measuring PHI leakage and downstream utility across image-side, text-side, and combined de-identification settings. Results show that OCR-only masking is not sufficient as a standalone solution, and restoration-based sanitization better preserves clinically relevant visual context while sharply reducing recoverable PHI.

医疗AI隐私保护生成修复多模态

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。