Exploring the Relationship Between Privacy and Utility in Mobile Health: Algorithm Development and Validation via Simulations of Federated Learning, Differential Privacy, and External Attacks.

Exploring the Relationship Between Privacy and Utility in Mobile Health: Algorithm Development and Validation via Simulations of Federated Learning, Differential Privacy, and External Attacks.
复制标题

通过模拟联合学习,差异隐私和外部攻击,探索移动健康中隐私与效用之间的关系:算法开发和验证。

DOI:
10.2196/43664
复制
发表时间:
2023-04-20
影响因子:
7.4
通讯作者:
Tewari, Ambuj
Tewari, Ambuj
中科院分区:
医学2区
文献类型:
--
作者:
Shen, Alexander;Francisco, Luke;Sen, Srijan;Tewari, Ambuj

文献摘要

参考文献

被引文献

相似文献

尽管支持大规模移动医疗(mHealth)系统可行性的证据不断增加,但隐私保护仍然是一个重要的实施挑战。公开可用的移动医疗应用程序的潜在规模以及所涉及数据的敏感性,将不可避免地吸引那些寻求损害用户隐私的敌对行为者的不必要的关注。尽管联邦学习(FL)和差分隐私(DP)等隐私保护技术提供了强有力的理论保证,但尚不清楚这些技术在现实世界条件下的实际表现如何。利用密歇根大学实习生健康研究(IHS)的数据,我们评估了FL和DP在相关模型准确性和训练时间方面的隐私保护能力。通过对目标移动医疗系统的模拟外部攻击,我们旨在测量目标系统上不同隐私保护级别下这种攻击的有效性,并测量与所选隐私保护级别相关的目标系统性能成本。我们的目标系统是一个神经网络分类器,它试图从传感器数据中预测IHS参与者的日常情绪生态瞬间评估得分。外部攻击者试图识别平均情绪生态瞬时评估得分低于全球平均水平的参与者。攻击遵循了文献中的技术,给出了攻击者能力的相关假设。为了测量攻击有效性,我们收集了攻击成功指标(曲线下面积[AUC],正预测值和灵敏度),为了测量隐私成本,我们计算了目标模型训练时间并测量了模型效用指标。这两组指标都是在目标上不同程度的隐私保护下报告的。我们发现,单独使用FL并不能提供足够的保护来抵御上面提出的隐私攻击,在最坏的情况下,攻击者在确定哪些参与者表现出低于平均情绪的AUC超过0.90。然而,在本研究测试的最高DP水平下,攻击者的AUC下降到约0.59,目标的R2仅下降了10%,模型训练时间增加了43%。攻击阳性预测值和敏感性也有相似的趋势。最后,我们表明,IHS中最可能需要强大隐私保护的参与者也最容易受到这种特定隐私攻击的风险,并且随后从这些隐私保护技术中获益最多。我们的研究结果既证明了主动隐私保护研究的必要性,也证明了当前FL和DP方法在实际移动医疗场景中实施的可行性。我们的模拟方法使用高度可解释的指标表征了移动医疗设置中的隐私-效用权衡,为未来研究数据驱动的健康和医疗应用中的隐私保护技术提供了框架。
Although evidence supporting the feasibility of large-scale mobile health (mHealth) systems continues to grow, privacy protection remains an important implementation challenge. The potential scale of publicly available mHealth applications and the sensitive nature of the data involved will inevitably attract unwanted attention from adversarial actors seeking to compromise user privacy. Although privacy-preserving technologies such as federated learning (FL) and differential privacy (DP) offer strong theoretical guarantees, it is not clear how such technologies actually perform under real-world conditions. Using data from the University of Michigan Intern Health Study (IHS), we assessed the privacy protection capabilities of FL and DP against the trade-offs in the associated model’s accuracy and training time. Using a simulated external attack on a target mHealth system, we aimed to measure the effectiveness of such an attack under various levels of privacy protection on the target system and measure the costs to the target system’s performance associated with the chosen levels of privacy protection. A neural network classifier that attempts to predict IHS participant daily mood ecological momentary assessment score from sensor data served as our target system. An external attacker attempted to identify participants whose average mood ecological momentary assessment score is lower than the global average. The attack followed techniques in the literature, given the relevant assumptions about the abilities of the attacker. For measuring attack effectiveness, we collected attack success metrics (area under the curve [AUC], positive predictive value, and sensitivity), and for measuring privacy costs, we calculated the target model training time and measured the model utility metrics. Both sets of metrics are reported under varying degrees of privacy protection on the target. We found that FL alone does not provide adequate protection against the privacy attack proposed above, where the attacker’s AUC in determining which participants exhibit lower than average mood is over 0.90 in the worst-case scenario. However, under the highest level of DP tested in this study, the attacker’s AUC fell to approximately 0.59 with only a 10% point decrease in the target’s R2 and a 43% increase in model training time. Attack positive predictive value and sensitivity followed similar trends. Finally, we showed that participants in the IHS most likely to require strong privacy protection are also most at risk from this particular privacy attack and subsequently stand to benefit the most from these privacy-preserving technologies. Our results demonstrated both the necessity of proactive privacy protection research and the feasibility of the current FL and DP methods implemented in a real mHealth scenario. Our simulation methods characterized the privacy-utility trade-off in our mHealth setup using highly interpretable metrics, providing a framework for future research into privacy-preserving technologies in data-driven health and medical applications.
DOI: 10.2196/31097
发表时间: 2021-09-08
影响因子: 5
作者:
Cao J;Lim Y;Sengoku S;Guo X;Kodama K
通讯作者: Kodama K
DOI: 10.1038/s41591-021-01506-3
发表时间: 2021-10
期刊: NATURE MEDICINE
影响因子: 82.9
作者:
Dayan, Ittai;Roth, Holger R.;Zhong, Aoxiao;Harouni, Ahmed;Gentili, Amilcare;Abidin, Anas Z.;Liu, Andrew;Costa, Anthony Beardsworth;Wood, Bradford J.;Tsai, Chien-Sung;Wang, Chih-Hung;Hsu, Chun-Nan;Lee, C. K.;Ruan, Peiying;Xu, Daguang;Wu, Dufan;Huang, Eddie;Kitamura, Felipe Campos;Lacey, Griffin;de Antonio Corradi, Gustavo Cesar;Nino, Gustavo;Shin, Hao-Hsin;Obinata, Hirofumi;Ren, Hui;Crane, Jason C.;Tetreault, Jesse;Guan, Jiahui;Garrett, John W.;Kaggie, Joshua D.;Park, Jung Gil;Dreyer, Keith;Juluru, Krishna;Kersten, Kristopher;Rockenbach, Marcio Aloisio Bezerra Cavalcanti;Linguraru, Marius George;Haider, Masoom A.;AbdelMaseeh, Meena;Rieke, Nicola;Damasceno, Pablo F.;Silva, Pedro Mario Cruz E.;Wang, Pochuan;Xu, Sheng;Kawano, Shuichi;Sriswasdi, Sira;Park, Soo Young;Grist, Thomas M.;Buch, Varun;Jantarabenjakul, Watsamon;Wang, Weichung;Tak, Won Young;Li, Xiang;Lin, Xihong;Kwon, Young Joon;Quraini, Abood;Feng, Andrew;Priest, Andrew N.;Turkbey, Baris;Glicksberg, Benjamin;Bizzo, Bernardo;Kim, Byung Seok;Tor-Diez, Carlos;Lee, Chia-Cheng;Hsu, Chia-Jung;Lin, Chin;Lai, Chiu-Ling;Hess, Christopher P.;Compas, Colin;Bhatia, Deepeksha;Oermann, Eric K.;Leibovitz, Evan;Sasaki, Hisashi;Mori, Hitoshi;Yang, Isaac;Sohn, Jae Ho;Murthy, Krishna Nand Keshava;Fu, Li-Chen;Furtado de Mendonca, Matheus Ribeiro;Fralick, Mike;Kang, Min Kyu;Adil, Mohammad;Gangai, Natalie;Vateekul, Peerapon;Elnajjar, Pierre;Hickman, Sarah;Majumdar, Sharmila;McLeod, Shelley L.;Reed, Sheridan;Graf, Stefan;Harmon, Stephanie;Kodama, Tatsuya;Puthanakit, Thanyawee;Mazzulli, Tony;de Lavor, Vitor Lima;Rakvongthai, Yothin;Lee, Yu Rim;Wen, Yuhong;Gilbert, Fiona J.;Flores, Mona G.;Li, Quanzheng
通讯作者: Li, Quanzheng
DOI: 10.2196/20891
发表时间: 2020-10-26
影响因子: 7.4
作者:
Lee GH;Shin SY
通讯作者: Shin SY
DOI: 10.1093/bioinformatics/btz373
发表时间: 2019-07-15
期刊: BIOINFORMATICS
影响因子: 5.8
作者:
Niinimaki, Teppo;Heikkila, Mikko A.;Kaski, Samuel
通讯作者: Kaski, Samuel
DOI: 10.1109/jbhi.2020.2999497
发表时间: 2020-08-01
影响因子: 7.7
作者:
Liu, Xin;Zhou, Pan;Wu, Dapeng Oliver
通讯作者: Wu, Dapeng Oliver