Electronic health records (EHR) often contain sensitive medical information about individual patients, posing significant limitations to sharing or releasing EHR data for downstream learning and inferential tasks. We use normalizing flows (NF), a family of deep generative models, to estimate the probability density of a dataset with differential privacy (DP) guarantees, from which privacy-preserving synthetic data are generated. We apply the technique to an EHR dataset containing patients with pulmonary hypertension. We assess the learning and inferential utility of the synthetic data by comparing the accuracy in the prediction of the hypertension status and variational posterior distribution of the parameters of a physics-based model. In addition, we use a simulated dataset from a nonlinear model to compare the results from variational inference (VI) based on privacy-preserving synthetic data, and privacy-preserving VI obtained from directly privatizing NFs for VI with DP guarantees given the original non-private dataset. The results suggest that synthetic data generated through differentially private density estimation with NF can yield good utility at a reasonable privacy cost. We also show that VI obtained from differentially private NF based on the free energy bound loss may produce variational approximations with significantly altered correlation structure, and loss formulations based on alternative dissimilarity metrics between two distributions might provide improved results.
翻译:电子健康记录(EHR)常包含患者个体的敏感医疗信息,这严重限制了为下游学习与推断任务而共享或发布EHR数据的可行性。我们采用标准化流(NF)——一类深度生成模型——在差分隐私(DP)保障下估计数据集的概率密度,进而生成保护隐私的合成数据。该方法应用于包含肺动脉高压患者的EHR数据集。通过比较高血压状态预测精度及物理模型参数的变分后验分布,评估合成数据的学习与推断效用。此外,基于非线性模型模拟数据集,我们比较了基于隐私保护合成数据的变分推断(VI)结果,以及直接对原始非私有数据集的NF进行DP私有化后获得的隐私保护VI结果。研究表明,通过NF差分隐私密度估计生成的合成数据,能在合理隐私成本下取得良好效用。同时发现,基于自由能边界损失的差分隐私NF得到的变分近似可能产生显著改变的相关结构,而基于两种分布间替代差异性度量的损失函数有望改善结果。