Tech

AI endangers patient data – researchers are calling for new standards

Artificial intelligence is changing the way diseases are diagnosed. But new analyzes reveal security gaps in the processing of sensitive data using AI in medicine. For example, it can be proven with great precision whether a specific person’s data was used to train a model. This poses concrete risks for everyday life and the digital security of patients.

An international team of researchers from the Technical University of Munich, the Hasso Plattner Institute and Imperial College London has investigated the safety of artificial intelligence in healthcare. The results, published in the journal Nature, show a significant risk for patients whose data was used for training. In the study, researchers tested attacks on models based on seven established datasets containing imaging data, cardiograms and electronic medical records.

The results reveal gaps in previous security tests. While attacks on entire data sets usually failed, individual people could be recognized with a probability of almost 100 percent. Because if attackers have access to the clinic’s system and a single patient data sheet, a digital trail is created. If it can be proven that the data point has been incorporated into a specific AI model for special therapies, this indirectly reveals the illness of the person affected.

The weak points of AI in medicine

Daniel Rückert, Professor of AI in Medicine at the Technical University of Munich, says:

This is not a bearable risk. Health data is highly sensitive. (…) This is particularly serious because discrimination through AI also plays a role in medicine and, for example, some models make less accurate predictions if the patient belongs to a minority.

The larger and more complex the model is, the easier it is for re-identification attacks to succeed. The software’s memory behaves similarly to an accurate photo memory. Detailed features are so deeply imprinted that individual traces remain visible.

This can have serious consequences in everyday life for those affected. If information about participation in studies reaches insurance companies through third-party providers, there could be a risk of financial disadvantages. Risk profiles could be adjusted, leading to higher premiums for supplementary insurance.

People who are underrepresented in the data set, such as minorities or people with special organ characteristics, are particularly at risk. Anyone who voluntarily donates their own data to research may have to fear disadvantages for years to come.

Solutions for more data protection

In order to effectively protect patients, research is suggesting new technical protection mechanisms. A promising method is the so-called differential privacy, in which data protection forms the basis. With this approach, a system overlays the data material with targeted, minimal noise.

This can be compared to a slightly milky glass. The overall picture and medical details remain clearly visible to the computer, but the individual’s face becomes unrecognizable. In addition to technical adjustments, experts are demanding new standards for testing procedures.

In the future, security tests will have to measure the individual risk of each person instead of relying on an overall average. In addition, strict control of access to the AI ​​models themselves is essential. This would ensure scientific progress without endangering the confidentiality of patient data.

Also interesting:

Source link

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Close

Adblock Detected

kindly turn off ad blocker to browse freely