Differential privacy for medical deep learning: methods, tradeoffs, and deployment implications
arXiv:2506.00660 · doi:10.1038/s41746-025-02280-z
Abstract
Differential privacy (DP) is a key technique for protecting sensitive patient data in medical deep learning (DL). As clinical models grow more data-dependent, balancing privacy with utility and fairness has become a critical challenge. This scoping review synthesizes recent developments in applying DP to medical DL, with a particular focus on DP-SGD and alternative mechanisms across centralized and federated settings. Using a structured search strategy, we identified 74 studies published up to March 2025. Our analysis spans diverse data modalities, training setups, and downstream tasks, and highlights the tradeoffs between privacy guarantees, model accuracy, and subgroup fairness. We find that while DP-especially at strong privacy budgets-can preserve performance in well-structured imaging tasks, severe degradation often occurs under strict privacy, particularly in underrepresented or complex modalities. Furthermore, privacy-induced performance gaps disproportionately affect demographic subgroups, with fairness impacts varying by data type and task. A small subset of studies explicitly addresses these tradeoffs through subgroup analysis or fairness metrics, but most omit them entirely. Beyond DP-SGD, emerging approaches leverage alternative mechanisms, generative models, and hybrid federated designs, though reporting remains inconsistent. We conclude by outlining key gaps in fairness auditing, standardization, and evaluation protocols, offering guidance for future work toward equitable and clinically robust privacy-preserving DL systems in medicine.
References in corpus (18)
- Deep Learning in Neural Networks: An Overview
- Deep Learning with Differential Privacy
- ChestX-ray8: Hospital-scale Chest X-ray Database and Benchmarks on Weakly-Supervised Classification and Localization of Common Thorax Diseases
- Model Cards for Model Reporting
- Renyi Differential Privacy
- A Survey of Privacy Attacks in Machine Learning
- Differentially Private Synthetic Medical Data Generation using Convolutional GANs
- Do Gradient Inversion Attacks Make Federated Learning Unsafe?
- Large Language Models Streamline Automated Machine Learning for Clinical Studies
- Recent Advances of Differential Privacy in Centralized Deep Learning: A Systematic Survey
- From large language models to multimodal AI: A scoping review on the potential of generative AI in medicine
- Private, fair and accurate: Training large-scale, privacy-preserving AI models in medical imaging
- Differentially Private Graph Classification with GNNs
- Efficient differentially private learning improves drug sensitivity prediction
- Federated learning for secure development of AI models for Parkinson's disease detection using speech from different languages
- The Impact of Speech Anonymization on Pathology and Its Limits
- Representation Transfer for Differentially Private Drug Sensitivity Prediction
- Differential privacy enables fair and accurate AI-based analysis of speech disorders while protecting patient data