about
Show HN: Our first published paper as an Independent Research Group (arxiv.org)
2 points by hsikka on Jul 17, 2020 | hide | past | pdf | discuss on HN

In plain words: Two ways of shielding patient images with mathematical privacy were tested: adding noise to each record before training, or adding noise while the network learns. The study measures how much accuracy falls as privacy gets stronger and whether those guarantees help in real hospitals.

Abstract · Benchmarking Differentially Private Residual Networks for Medical Imagery

In this paper we measure the effectiveness of $ε$-Differential Privacy (DP) when applied to medical imaging. We compare two robust differential privacy mechanisms: Local-DP and DP-SGD and benchmark their performance when analyzing medical imagery records. We analyze the trade-off between the model's accuracy and the level of privacy it guarantees, and also take a closer look to evaluate how useful these theoretical privacy guarantees actually prove to be in the real world medical setting.

Sahib Singh, Harshvardhan Sikka, Sasikanth Kotti, Andrew Trask
arXiv:2005.13099 · cs.LG, cs.CR, cs.CV, eess.IV, stat.ML · submitted May 27, 2020 · updated Sep 5, 2020
abstract · pdf · html · 5 Pages, 4 Figures

add comment on HN