Patient Privacy in Differentially Private Diagnostic Models

dc.contributor.authorJärv, Priit
dc.contributor.authorPahikkala, Tapio
dc.contributor.authorAirola, Antti
dc.contributor.organizationfi=terveysteknologia|en=Health Technology|
dc.contributor.organizationfi=data-analytiikka|en=Data-analytiikka|
dc.contributor.organization-code1.2.246.10.2458963.20.28696315432
dc.contributor.organization-code1.2.246.10.2458963.20.68940835793
dc.converis.publication-id526899103
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/526899103
dc.date.accessioned2026-08-04T20:12:40Z
dc.description.abstract<p>Differential privacy gives a theoretical guarantee against inferring the presence of a patient in the training data of a model. Patients can have multiple data records that are used as separate training inputs, but to apply differential privacy we must view the contribution of a patient as a single privacy unit. The main approaches are user level privacy that uses all records of the patient as the privacy unit, group privacy which simplifies computation by allowing each patient to have at most <em>k</em> records, and sample level privacy that requires each patient to contribute one record. Of these, sample level privacy is well supported by efficient deep learning libraries and can be adapted to group privacy. User level differential privacy in the medical domain remains poorly supported by software and, as a consequence, unexplored. We compare these three approaches in experiments with cardiovascular disease and melanoma datasets. We found that in case most patients contribute only a single data record, sample level privacy suffices. With all patients contributing multiple records, user level privacy performed best, because it avoids the limitations of the alternative approaches: restricting the number of examples per patient, or inaccurately assuming all patients have the same number of records in privacy accounting.<br></p>
dc.format.pagerange15
dc.format.pagerange10
dc.identifier.isbn979-8-4007-2609-5
dc.identifier.urihttps://www.utupub.fi/handle/11111/62892
dc.identifier.urlhttps://doi.org/10.1145/3806007.3810963
dc.identifier.urnURN:NBN:fi-fe20260803114914
dc.language.isoen
dc.okm.affiliatedauthorJärv, Priit
dc.okm.affiliatedauthorPahikkala, Tapio
dc.okm.affiliatedauthorAirola, Antti
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryUnited Statesen_GB
dc.publisher.countryYhdysvallat (USA)fi_FI
dc.publisher.country-codeUS
dc.relation.conferenceInternational Workshop on Security and Privacy Analytics
dc.relation.doi10.1145/3806007.3810963
dc.titlePatient Privacy in Differentially Private Diagnostic Models
dc.title.bookIWSPA '26 : Proceedings of the 12th ACM International Workshop on Security and Privacy Analytics
dc.year.issued2026

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
3806007.3810963.pdf
Size:
1006.33 KB
Format:
Adobe Portable Document Format