[论文解读] Privacy-Preserving and Trustworthy Deep Learning for Medical Imaging
本文提出了一套系统性框架,将隐私增强技术(PETs)整合到深度放射组学中,以确保医学影像中的隐私性和可信性。该框架对PETs进行分类,提出混合PET构造方法,并为PETs在整个深度放射组学流程中的集成提供分类法,同时提供关于挑战和未来研究方向的技术见解。
The shift towards efficient and automated data analysis through Machine Learning (ML) has notably impacted healthcare systems, particularly Radiomics. Radiomics leverages ML to analyze medical images accurately and efficiently for precision medicine. Current methods rely on Deep Learning (DL) to improve performance and accuracy (Deep Radiomics). Given the sensitivity of medical images, ensuring privacy throughout the Deep Radiomics pipeline-from data generation and collection to model training and inference-is essential, especially when outsourced. Thus, Privacy-Enhancing Technologies (PETs) are crucial tools for Deep Radiomics. Previous studies and systematization efforts have either broadly overviewed PETs and their applications or mainly focused on subsets of PETs for ML algorithms. In Deep Radiomics, where efficiency, accuracy, and privacy are crucial, many PETs, while theoretically applicable, may not be practical without specialized optimizations or hybrid designs. Additionally, not all DL models are suitable for Radiomics. Consequently, there is a need for specialized studies that investigate and systematize the effective and practical integration of PETs into the Deep Radiomics pipeline. This work addresses this research gap by (1) classifying existing PETs, presenting practical hybrid PETS constructions, and a taxonomy illustrating their potential integration with the Deep Radiomics pipeline, with comparative analyses detailing assumptions, architectural suitability, and security, (2) Offering technical insights, describing potential challenges and means of combining PETs into the Deep Radiomics pipeline, including integration strategies, subtilities, and potential challenges, (3) Proposing potential research directions, identifying challenges, and suggesting solutions to enhance the PETs in Deep Radiomics.
研究动机与目标
- 解决深度放射组学中隐私增强技术(PETs)实际集成方面缺乏专门研究的问题。
- 系统化整理现有PETs,并提出针对深度放射组学流程的混合构造方法。
- 基于假设、架构适用性及安全属性,对PETs进行对比分析。
- 提供关于将PETs整合到医学影像工作流中所面临挑战及整合策略的技术见解。
- 识别开放性挑战,并提出未来研究方向,以提升PETs在深度放射组学中的实用性。
提出的方法
- 对与深度放射组学相关的现有PETs进行分类与归类,包括同态加密、安全多方计算和差分隐私。
- 提出实用的混合PET构造方法,结合多种隐私技术以提升效率与安全性。
- 开发一种分类法,将PETs映射到深度放射组学流程的不同阶段:数据采集、模型训练、推理和部署。
- 分析各类PET在不同流程阶段的架构适用性、威胁模型假设及安全保证。
- 将PETs与卷积神经网络(CNNs)及随机梯度下降(SGD)结合,实现高效且隐私保护的训练。
- 评估在联邦学习和集中式设置下,于梯度、输入和标签层级应用差分隐私(DP)的可行性。

实验结果
研究问题
- RQ1哪些PETs最适合深度放射组学流程的不同阶段,以及如何有效组合使用?
- RQ2混合PET架构如何改善深度放射组学中隐私性、准确性和计算效率之间的平衡?
- RQ3在医学影像中的非凸深度学习模型(如CNNs)中应用PETs——尤其是差分隐私——面临哪些关键挑战?
- RQ4如何将PETs集成到联邦学习和集中式训练中,以防范成员推断攻击和模型提取攻击?
- RQ5在放射组学中部署可信且隐私保护的深度学习方面,存在哪些关键开放挑战和未来研究方向?
主要发现
- 在SGD中对梯度应用差分隐私(DP)可显著降低成员推断攻击(MIAs)和模型提取攻击(MEAs)的成功率。
- 集中式差分隐私(CDP)与本地差分隐私(LDP)在隐私与准确率之间提供不同的权衡,当中心聚合器可信时,CDP更为有效。
- 混合PET构造(如结合MPC与DP)可增强安全性,同时减轻深度学习模型中的噪声累积问题。
- 在非凸模型中,对输入数据或模型输出应用DP的效果不如梯度层级DP,原因在于缺乏闭式敏感度分析。
- 目标扰动在隐私保护机器学习(PPML)中具有潜力,但在深度放射组学中仍具挑战,原因在于CNN损失函数的非凸性。
- 将PETs整合到深度放射组学流程中,需要精心的架构设计,以在隐私性、模型准确率和计算开销之间实现平衡。

更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。