Exploring the Relationship Between Privacy and Utility in Mobile Health: Algorithm Development and Validation via Simulations of Federated Learning, Differential Privacy, and External Attacks

被引:3
作者
Shen, Alexander [1 ,2 ]
Francisco, Luke [1 ]
Sen, Srijan [3 ,4 ]
Tewari, Ambuj [1 ,5 ]
机构
[1] Univ Michigan, Dept Stat, Ann Arbor, MI USA
[2] Carnegie Mellon Univ, Dept Stat & Data Sci, 5000 Forbes Ave, Pittsburgh, PA 15213 USA
[3] Univ Michigan, Eisenberg Family Depress Ctr, Ann Arbor, MI USA
[4] Univ Michigan, Mol & Behav Neurosci Inst, Ann Arbor, MI USA
[5] Univ Michigan, Dept Elect Engn & Comp Sci, Ann Arbor, MI USA
基金
美国国家卫生研究院;
关键词
privacy; data protection; machine learning; federated learning; neural networks; mobile health; mHealth; wearable electronic devices; differential privacy; learning; evidence; feasibility; applications; training; technology; mobile phone;
D O I
10.2196/43664
中图分类号
R19 [保健组织与事业(卫生事业管理)];
学科分类号
摘要
Background: Although evidence supporting the feasibility of large-scale mobile health (mHealth) systems continues to grow, privacy protection remains an important implementation challenge. The potential scale of publicly available mHealth applications and the sensitive nature of the data involved will inevitably attract unwanted attention from adversarial actors seeking to compromise user privacy. Although privacy-preserving technologies such as federated learning (FL) and differential privacy (DP) offer strong theoretical guarantees, it is not clear how such technologies actually perform under real-world conditions. Objective: Using data from the University of Michigan Intern Health Study (IHS), we assessed the privacy protection capabilities of FL and DP against the trade-offs in the associated model's accuracy and training time. Using a simulated external attack on a target mHealth system, we aimed to measure the effectiveness of such an attack under various levels of privacy protection on the target system and measure the costs to the target system's performance associated with the chosen levels of privacy protection. Methods: A neural network classifier that attempts to predict IHS participant daily mood ecological momentary assessment score from sensor data served as our target system. An external attacker attempted to identify participants whose average mood ecological momentary assessment score is lower than the global average. The attack followed techniques in the literature, given the relevant assumptions about the abilities of the attacker. For measuring attack effectiveness, we collected attack success metrics (area under the curve [AUC], positive predictive value, and sensitivity), and for measuring privacy costs, we calculated the target model training time and measured the model utility metrics. Both sets of metrics are reported under varying degrees of privacy protection on the target. Results: We found that FL alone does not provide adequate protection against the privacy attack proposed above, where the attacker's AUC in determining which participants exhibit lower than average mood is over 0.90 in the worst-case scenario. However, under the highest level of DP tested in this study, the attacker's AUC fell to approximately 0.59 with only a 10% point decrease in the target's R-2 and a 43% increase in model training time. Attack positive predictive value and sensitivity followed similar trends. Finally, we showed that participants in the IHS most likely to require strong privacy protection are also most at risk from this particular privacy attack and subsequently stand to benefit the most from these privacy-preserving technologies. Conclusions: Our results demonstrated both the necessity of proactive privacy protection research and the feasibility of the current FL and DP methods implemented in a real mHealth scenario. Our simulation methods characterized the privacy-utility trade-off in our mHealth setup using highly interpretable metrics, providing a framework for future research into privacy-preserving technologies in data-driven health and medical applications.
引用
收藏
页数:15
相关论文
共 28 条
[1]   Deep Learning with Differential Privacy [J].
Abadi, Martin ;
Chu, Andy ;
Goodfellow, Ian ;
McMahan, H. Brendan ;
Mironov, Ilya ;
Talwar, Kunal ;
Zhang, Li .
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, :308-318
[2]  
[Anonymous], IHS PRIV PAP
[3]  
Auxier B., 2019, Americans and Privacy: Concerned, Confused and Feeling Lack of Control over Their Personal Information
[4]   Multiple imputation by chained equations: what is it and how does it work? [J].
Azur, Melissa J. ;
Stuart, Elizabeth A. ;
Frangakis, Constantine ;
Leaf, Philip J. .
INTERNATIONAL JOURNAL OF METHODS IN PSYCHIATRIC RESEARCH, 2011, 20 (01) :40-49
[5]   Federated learning of predictive models from federated Electronic Health Records [J].
Brisimi, Theodora S. ;
Chen, Ruidi ;
Mela, Theofanie ;
Olshevsky, Alex ;
Paschalidis, Ioannis Ch. ;
Shi, Wei .
INTERNATIONAL JOURNAL OF MEDICAL INFORMATICS, 2018, 112 :59-67
[6]  
Brooks C., 2021, Forbes
[7]   Privacy-preserving Federated Deep Learning for Wearable IoT-based Biomedical Monitoring [J].
Can, Yekta Said ;
Ersoy, Cem .
ACM TRANSACTIONS ON INTERNET TECHNOLOGY, 2021, 21 (01)
[8]   Exploring the Shift in International Trends in Mobile Health Research From 2000 to 2020: Bibliometric Analysis [J].
Cao, Jianfei ;
Lim, Yeongjoo ;
Sengoku, Shintaro ;
Guo, Xitong ;
Kodama, Kota .
JMIR MHEALTH AND UHEALTH, 2021, 9 (09)
[9]  
Choudhury O, 2020, Arxiv, DOI arXiv:1910.02578
[10]   Federated learning for predicting clinical outcomes in patients with COVID-19 [J].
Dayan, Ittai ;
Roth, Holger R. ;
Zhong, Aoxiao ;
Harouni, Ahmed ;
Gentili, Amilcare ;
Abidin, Anas Z. ;
Liu, Andrew ;
Costa, Anthony Beardsworth ;
Wood, Bradford J. ;
Tsai, Chien-Sung ;
Wang, Chih-Hung ;
Hsu, Chun-Nan ;
Lee, C. K. ;
Ruan, Peiying ;
Xu, Daguang ;
Wu, Dufan ;
Huang, Eddie ;
Kitamura, Felipe Campos ;
Lacey, Griffin ;
de Antonio Corradi, Gustavo Cesar ;
Nino, Gustavo ;
Shin, Hao-Hsin ;
Obinata, Hirofumi ;
Ren, Hui ;
Crane, Jason C. ;
Tetreault, Jesse ;
Guan, Jiahui ;
Garrett, John W. ;
Kaggie, Joshua D. ;
Park, Jung Gil ;
Dreyer, Keith ;
Juluru, Krishna ;
Kersten, Kristopher ;
Rockenbach, Marcio Aloisio Bezerra Cavalcanti ;
Linguraru, Marius George ;
Haider, Masoom A. ;
AbdelMaseeh, Meena ;
Rieke, Nicola ;
Damasceno, Pablo F. ;
Silva, Pedro Mario Cruz E. ;
Wang, Pochuan ;
Xu, Sheng ;
Kawano, Shuichi ;
Sriswasdi, Sira ;
Park, Soo Young ;
Grist, Thomas M. ;
Buch, Varun ;
Jantarabenjakul, Watsamon ;
Wang, Weichung ;
Tak, Won Young .
NATURE MEDICINE, 2021, 27 (10) :1735-+