PubMed دسترسی آزاد

Privacy Leakage in Federated Learning in Radiology Reports: Comparative Evaluation of Tokenizer and Batch-Size Privacy Risks.

استودیوی صوتی مقاله

پخش حرفه‌ای فارسی و انگلیسی

در حال بررسی نسخه‌های صوتی ذخیره‌شده…

صوت تولیدشده با هوش مصنوعی است. برای کاربرد علمی یا درمانی، متن و منبع اصلی را بررسی کنید.
خواندن هوشمند فارسی و انگلیسی در حال آماده‌سازی صداهای مرورگر…
تنظیم صدای طبیعی و سرعت

صداهایی که در نامشان «Natural»، «Neural» یا «Online» دیده می‌شود معمولاً طبیعی‌ترند. انتخاب صدا به صداهای نصب‌شده در ویندوز و مرورگر شما بستگی دارد.

چکیده اصلی

BACKGROUND: Federated learning (FL) enables multi-institutional model training on clinical text without sharing raw data; however, gradient inversion methods can reconstruct sensitive information from shared model updates. The extent of such privacy leakage in FL applied to radiology reports, and the role of tokenizer design, remains unclear. OBJECTIVE: This study aimed to quantify gradient-based reconstruction of radiology report text in an FL setting and to compare privacy risk across 3 transformer tokenization strategies in a controlled, tokenizer-aware evaluation. METHODS: Six FL clients trained a GPT-2-style transformer (sequence length 32) on 2 public clinical-text corpora comprising 368,751 diagnostic reports, 98,206 discharge summaries, and 1500 MIMIC-CXR (Medical Information Mart for Intensive Care Chest X-Ray) radiology reports. Models were trained using 3 tokenizers (GPT-2, RadBERT, and LLaMA-2) with batch sizes of 64, 128, and 256. An active malicious-server threat model was assumed, and analytic gradient inversion was applied to recover text. Reconstruction fidelity was measured over 5 runs using exact sentence accuracy, sentence-level bilingual evaluation understudy (S-BLEU), and recall-oriented understudy for gisting evaluation (ROUGE-L). RESULTS: Exact sentence reconstruction ranged from 27% to 75% across tokenizers, datasets, and batch sizes. At batch size 64 on the discharge dataset, accuracy was 64.7% (GPT-2), 70% (RadBERT), and 67.5% (LLaMA-2), decreasing to 27.3%, 28.5%, and 27.5% at batch size 256. S-BLEU declined with increasing batch size (eg, discharge reports from 0.69 to 0.31). Reconstruction fidelity did not differ significantly across tokenizers (all but one of 27 comparisons nonsignificant; none significant after Holm correction), and approximately 75% of clinical concepts were represented in the reconstructed text (a corpus-level upper bound), regardless of tokenizer. Batch size was the dominant factor governing leakage. CONCLUSIONS: Under a worst-case malicious server that tampers with the shared model and observes unprotected per-client gradients (no secure aggregation or differential privacy), substantial portions of radiology-report text can be reconstructed, with up to approximately 75% of reconstructed 32-token sequences and 75% of clinical concepts (not direct patient identifiers) recovered from FL gradients. In a controlled ablation holding model architecture fixed, tokenizer choice, including domain-specific tokenizers, did not significantly affect leakage under the evaluated conditions, whereas batch size was the primary determinant, and no tokenizer significantly reduced the risk. Tokenizer selection should therefore not be treated as a privacy safeguard in this setting. Safeguards such as secure aggregation and differential privacy should therefore be evaluated as candidate protections for FL deployments that must satisfy Health Insurance Portability and Accountability Act (HIPAA) and General Data Protection Regulation (GDPR) requirements in radiology natural language processing (NLP); legal compliance additionally depends on organizational safeguards, risk assessment, and governance beyond the scope of this study.

نتیجه فارسی

در این مطالعه، ریسک نشت اطلاعات حساس از طریق روش‌های معکوس‌سازی گرادیان در یادگیری فدرال برای گزارش‌های رادیولوژی بررسی شد. نتایج نشان داد که با وجود استفاده از توکن‌سازهای مختلف، بازسازی بخش قابل توجهی از متن گزارش‌ها (تا حدود ۷۵٪ مفاهیم بالینی) امکان‌پذیر است. عامل اصلی حاکم بر شدت نشت، اندازه دسته (batch size) بود و انتخاب توکن‌ساز تأثیر معناداری بر کاهش ریسک نداشت.

  • بازسازی جملات دقیق گزارش‌های رادیولوژی در محیط FL بین ۲۷٪ تا ۷۵٪ متغیر بود.
  • اندازه دسته (batch size) عامل اصلی حاکم بر شدت نشت اطلاعات بود.
  • انتخاب توکن‌ساز (از جمله توکن‌سازهای تخصصی حوزه) تأثیر معناداری بر کاهش ریسک نشت نداشت.
  • در شرایط بدترین حالت (سرور مخرب و بدون محافظت)، بخش‌های قابل توجهی از متن گزارش‌ها قابل بازسازی بودند.
  • توکن‌ساز نباید به عنوان یک محافظ حریم خصوصی در این محیط تلقی شود.

ترجمه فارسی چکیده

یادگیری فدرال (FL) امکان آموزش مدل‌های چندمؤسسه‌ای بر روی متون بالینی را بدون به اشتراک گذاشتن داده‌های خام فراهم می‌کند، اما روش‌های معکوس‌سازی گرادیان می‌توانند اطلاعات حساس را از به‌روزرسانی‌های مدل به‌دست آورند. این مطالعه هدف دارد میزان بازسازی متون گزارش‌های رادیولوژی بر پایه گرادیان را در محیط FL کمی‌سازی کند و ریسک‌های حریم خصوصی را در ۳ استراتژی توکن‌سازی مختلف مقایسه نماید. شش کلاینت FL مدل ترنسفورمر سبک GPT-2 را بر روی ۳ مجموعه داده متنی بالینی عمومی آموزش دادند. مدل‌ها با ۳ توکن‌ساز (GPT-2، RadBERT و LLaMA-2) و با اندازه‌های دسته ۶۴، ۱۲۸ و ۲۵۶ آموزش یافتند. یک مدل تهدید سرور مخرب فعال فرض شد و معکوس‌سازی تحلیلی گرادیان برای بازسازی متن به کار گرفته شد. دقت بازسازی با استفاده از معیارهای S-BLEU و ROUGE-L اندازه‌گیری شد. نتایج نشان داد که دقت بازسازی جملات دقیق بین ۲۷٪ تا ۷۵٪ متغیر بود. اندازه دسته عامل اصلی حاکم بر نشت اطلاعات بود و انتخاب توکن‌ساز تأثیر معناداری بر ریسک نشت نداشت.

روش پژوهش

شش کلاینت FL مدل ترنسفورمر سبک GPT-2 را بر روی سه مجموعه داده متنی بالینی عمومی آموزش دادند. مدل‌ها با سه توکن‌ساز (GPT-2، RadBERT و LLaMA-2) و با اندازه‌های دسته ۶۴، ۱۲۸ و ۲۵۶ آموزش یافتند. معکوس‌سازی تحلیلی گرادیان برای بازسازی متن به کار گرفته شد.

محدودیت‌ها

محدودیت‌های مطالعه شامل فرض یک مدل تهدید سرور مخرب فعال و عدم استفاده از محافظت‌هایی مانند تجمیع امن و حریم خصوصی تفاضلی است.

استخراج ساختاریافته از متن منبع

نمای PICO و پیامدها

جمعیت
مجموعه داده‌های متنی بالینی شامل ۳۶۸،۷۵۱ گزارش تشخیصی، ۹۸،۲۰۶ خلاصه ترخیص و ۱۵۰۰ گزارش عکس‌برداری قفسه سینه MIMIC-CXR بود.
مداخله/مواجهه
استفاده از سه توکن‌ساز مختلف (GPT-2، RadBERT و LLaMA-2) و سه اندازه دسته مختلف (۶۴، ۱۲۸ و ۲۵۶) در محیط یادگیری فدرال.
مقایسه
مقایسه دقت بازسازی متن و ریسک نشت بین توکن‌سازها و اندازه‌های دسته مختلف.
حجم نمونه
مجموع ۴۶۸،۷۵۷ گزارش (۳۶۸،۷۵۱ گزارش تشخیصی، ۹۸،۲۰۶ خلاصه ترخیص و ۱۵۰۰ گزارش MIMIC-CXR).

متن کامل اصلی

نسخه دارای مجوز در منبع علمی در دسترس است.

لینک مستقیم از metadata منبع گرفته شده و در تب جدید باز می‌شود.

باز کردن متن کامل

کلیدواژه‌ها

GDPRGeneral Data Protection RegulationHIPAAHealth Insurance Portability and Accountability Actdata securityfederated learninggradient inversionlarge language modelspatient confidentialityprivacyradiologytransformer models
در همین زیرشاخه

مقاله‌های مرتبط

PubMed2026

Personality Disorder Diagnoses in Outpatient Forensic Mental Health: A Comprehensive Prevalence Study in the Netherlands.

Personality disorders (PDs) are associated with significant clinical and societal consequences and are highly comorbid with other psychiatric conditions. In forensic mental health settings, PD diagnoses are particularly relevant because they are linked to antisocial behavior, recidivism risk, and specific treatment needs. However, empirical knowledge about the prevalence of PD diagnoses in outpatient forensic mental health (OFMH) care …

PubMed2026

Business Associates' Involvement in US Health Care Data Breaches: Longitudinal Analysis.

BACKGROUND: Health care organizations increasingly rely on business associates (BAs) to provide clinical, administrative, and technology services that require access to protected health information. While the Health Information Technology for Economic and Clinical Health (HITECH) Act and the Health Insurance Portability and Accountability Act (HIPAA) Omnibus Rule extended legal liability to BAs, the frequency and characteristics of dat…

PubMed2026

Digital Twin-Assisted Risk Disclosure in Adults Undergoing Elective Bronchoscopy: Multicenter Randomized Controlled Trial.

BACKGROUND: Risk disclosure before bronchoscopy should provide sufficient information for informed consent, but detailed text-based risk disclosure may increase procedural anxiety. Patient-specific visualization with a digital twin-based bronchoscopy simulator may help patients understand bronchoscopy and its risks in a more individualized manner. OBJECTIVE: This study evaluated whether digital twin-assisted risk disclosure reduces pre…

PubMed2026

Paediatric biobanking in the era of precision medicine: ethical, regulatory, and scientific challenges from childhood to adulthood.

UNLABELLED: Biobanks are increasingly central to precision medicine, particularly in rare diseases and paediatric oncology, where small and molecularly heterogeneous populations make access to high-quality, longitudinally annotated biological material essential. This narrative review examines the scientific value of paediatric biobanking and the ethical, regulatory, and organisational challenges that distinguish it from adult biobankin…