[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-117924-en":3,"doc-seo-117924-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},117924,16904993612988,"Olivia Brown","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","Machine learning models in trusted research environments - understanding operational risks","Trusted research environments (TREs) enable secure access to highly sensitive data, relying on manual output checks to minimize residual disclosure risk. While traditional disclosure controls are well established, machine learning introduces new disclosure threats driven by both the nature and the scale of model development. This article presents conceptual problems for TRE managers, demonstrates qualitatively different operational risk compared with conventional statistical outputs, highlights unresolved issues and uncertainties, and outlines remedial response options for safer ML use.","International Journal of Population Data Science (2023) 8:1:30  \n\n| International Journal of\u003Cbr>Population Data Science\u003Cbr>[Journal Website: www.ijpds.org](Journal Website: www.ijpds.org) |  |\n| --- | --- |\n| Machine learning models in trusted research environments – understanding operational risks\u003Cbr>Felix Ritchie1, ∗ , Amy Tilbrook2 , Christian Cole3 , Emily Jefferson3 , Susan Krueger4 , Esma Mansouri-Benssassi5 , Simon Rogers6 , and Jim Smith7 |  |\n\n\n| Submission History |  |\n| --- | --- |\n| Submitted: | 30/04/2023 |\n| Accepted: | 30/10/2023 |\n| Published: | 14/12/2023 |\n\n1 Bristol Business School, University of the West of England, Coldharbour Lane, Bristol BS16 1QY  \n2 University of Edinburgh, South Bridge, Edinburgh EH8 9YL  \n3 Division of Population Health and Genomics, Ninewells Hospital and Medical School, Dundee DD1 9SY  \n4 Health Informatics Centre, Ninewells Hospital and Medical School, Dundee DD1 9SY  \n5AffectiveHalo Ltd, Tom Morris Drive, St Andrews. KY16 8HS  \n6 NHS National Services Scotland, Gyle Square, 1 South Gyle Crescent, Edinburgh EH12 9EB  \n7 School of Computer Science and Creative Technologies, University of the West of England, Coldharbour Lane, Bristol BS16 1QY  \nAbstract  \nIntroduction  \nTrusted research environments (TREs) provide secure access to very sensitive data for research. All TREs operate manual checks on outputs to ensure there is no residual disclosure risk. Machine learning (ML) models require very large amount of data; if this data is personal, the TRE is a wellestablished data management solution. However, ML models present novel disclosure risks, in both type and scale.  \nObjectives  \nAs part of a series on ML disclosure risk in TREs, this article is intended to introduce TRE managers to the conceptual problems and work being done to address them.  \nMethods  \nWe demonstrate how ML models present a qualitatively different type of disclosure risk, compared to traditional statistical outputs. These arise from both the nature and the scale of ML modelling.  \nResults  \nWe show that there are a large number of unresolved issues, although there is progress in many areas . We show where areas of uncertainty remain, as well as remedial responses available to TREs.  \nConclusions  \nAt this stage, disclosure checking of ML models is very much a specialist activity. However, TRE managers need a basic awareness of the potential risk in ML models to enable them to make sensible decisions on using TREs for ML model development.  \nKeywords  \nconfidentiality; output checking; machine learning; artificial intelligence; data enclave; trusted research environment  \n∗ Corresponding Author:  \nEmail Address: [felix.ritchie@uwe.ac.uk](felix.ritchie@uwe.ac.uk) (Felix Ritchie)  \n[https://doi.org/10.23889/ijpds.v8i1.2165](https://doi.org/10.23889/ijpds.v8i1.2165)  \nDecember 13, 2023 © The Authors. Open Access under CC BY 4.0 ([https://creativecommons.org/licenses/by/4.0/deed.en](https://creativecommons.org/licenses/by/4.0/deed.en))  \nRitchie F et al. International Journal of Population Data Science (2023) 8:1:30  \nIntroduction  \nThis paper is part of a series investigating the risks of Machine Learning (ML) model development and release from Trusted Research Environments (TREs) . This paper focuses on operational risks for TRE managers, and potential methods to combat them.  \nML models are growing in popularity, particularly in health where they can play an important role supporting clinical and operational practice. These models are trained to, for example, recognise early-stage carcinomas or predict demand for a service to improve resource scheduling.  \nML is “a subset of Artificial Intelligence, that automatically learns patterns from datasets. It can be used to help humans better understand complex data, or make predictions based upon new, unseen data” [1] . Unlike traditional statistical models, where the estimation method is specified by the researcher, ML models are provided with an approach to learning ","cbCainev9PbslvGJ","https://ap.wps.com/l/cbCainev9PbslvGJ","pdf",1312044,1,9,"English","en",105,"# Introduction\n# Objectives\n# Methods\n# Results\n# Conclusions","[{\"question\":\"What is a trusted research environment (TRE) and what is its main disclosure control mechanism?\",\"answer\":\"A TRE provides secure access to highly sensitive, often de-identified data for research. It typically uses manual checks on outputs to limit residual disclosure risk before any release.\"},{\"question\":\"Why do machine learning models create different disclosure risks compared with traditional statistical outputs?\",\"answer\":\"Machine learning risks differ in both type and scale. The modelling process can interrogate data in multiple stages and produce results that are harder to understand, even for the designer.\"},{\"question\":\"What guidance does the article provide for TRE managers considering ML model development?\",\"answer\":\"It explains operational issues and uncertainty areas, notes that disclosure checking for ML is specialist work, and emphasizes basic awareness so managers can make sensible decisions about using TREs for ML development.\"}]","Machine learning models in trusted research environments - understanding operational risks | PDF",1785680396,23,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"machine-learning-models-in-trusted-research-environments-understanding-operational-risks","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/machine-learning-models-in-trusted-research-environments-understanding-operational-risks/117924/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What is a trusted research environment (TRE) and what is its main disclosure control mechanism?","Question",{"text":75,"@type":76},"A TRE provides secure access to highly sensitive, often de-identified data for research. It typically uses manual checks on outputs to limit residual disclosure risk before any release.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"Why do machine learning models create different disclosure risks compared with traditional statistical outputs?",{"text":80,"@type":76},"Machine learning risks differ in both type and scale. The modelling process can interrogate data in multiple stages and produce results that are harder to understand, even for the designer.",{"name":82,"@type":73,"acceptedAnswer":83},"What guidance does the article provide for TRE managers considering ML model development?",{"text":84,"@type":76},"It explains operational issues and uncertainty areas, notes that disclosure checking for ML is specialist work, and emphasizes basic awareness so managers can make sensible decisions about using TREs for ML development.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":21,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]