[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-120574-en":3,"doc-seo-120574-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},120574,687197207919,"Theodora","https://ap-avatar.wpscdn.com/avatar/a000253d6f5f7c60be?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779446848396160552",8,"Research & Report","Privacy-Preserving Machine Learning (PPML) Inference for Clinically Actionable Models","Privacy-preserving machine learning inference methods are evaluated for their ability to protect intellectual property of models and reduce leakage of sensitive training data, while also safeguarding patient-related confidential information used by model users. A security analysis determines an appropriate per-user query limit using the European Spine Study Group adult spinal deformity dataset. A privacy-preserving tree-based inference framework is implemented with two attacker scenarios using progressively larger synthetic data, substitute model training via XGBoost, and comparisons of predictive performance, feature gain, split-point inclusion via heatmaps, and timing results.","Received 22 January 2025, accepted 5 February 2025, date of publication 10 February 2025, date of current version 4 March 2025. Digital Object Identifier 10.1109/ACCESS.2025.3540261  \nPrivacy-Preserving Machine Learning (PPML) Inference for Clinically Actionable Models  \nBARIS BALABAN1, SEYMA SELCAN MAGARA2,3, CAGLAR YILGOR4, ALTUG YUCEKUL4,  \nIBRAHIM OBEID5, JAVIER PIZONES6, FRANK KLEINSTUECK7, FRANCISCO JAVIER SANCHEZ PEREZ-GRUESO6, FERRAN PELLISÉ8, AHMET ALANAY4, ERKAY SAVAS2,(Member, IEEE), ÇETIN BAĞCı9, AND OSMAN UGUR SEZERMAN 1, EUROPEAN SPINE STUDY GROUP  \n1Department of Biostatistics and Bioinformatics, Institute of Health Sciences, Acıbadem Mehmet Ali Aydınlar University, 34638 Istanbul, Türkiye  \n2Department of Computer Science and Engineering, Sabancı University, 34956 Istanbul, Türkiye  \n3Department of Computer Science, University of Tübingen, 72074 Tübingen, Germany  \n4Department of Orthopedics and Traumatology, Acibadem University School of Medicine, 34750 Istanbul, Türkiye  \n5Clinique du Dos, Elsan Jean Villar Private Hospital, 33520 Bordeaux, France  \n6 Spine Surgery Unit, Hospital Universitario La Paz, 28046 Madrid, Spain  \n7 Spine Center Division, Department of Orthopedics and Neurosurgery, Schulthess Klinik, 8008 Zürich, Switzerland  \n8 Spine Surgery Unit, Hospital Universitari Vall d’Hebron, 08035 Barcelona, Spain  \n9Bilmed Computer and Software Company, 34742 Istanbul, Türkiye Corresponding author: Baris Balaban ([Baris.Balaban@live.acibadem.edu.tr](Baris.Balaban@live.acibadem.edu.tr))  \nThe work of Erkay Savas was supported by the European Union’s Horizon Europe Research and Innovation Program under Grant 101079319.  \nThis work involved human subjects or animals in its research. Approval of all ethical and experimental procedures and protocols was granted by the Acibadem University Medical Research Evaluation Board (Acıbadem Üniversitesi Tıbbi Ara¸stırmalar Değerlendirme Kurulu-ATADEK) under Application No. 2019-11/34, and performed in line with the Declaration of Helsinki.  \nABSTRACT Machine learning (ML) refers to algorithms (often models) that are learned directly from data, germane to past experience. As algorithms have constantly been evolving with the exponential increase of computing power and vastly generated data, privacy of algorithms as well as of data becomes extremely important due to regulations and IP rights. Therefore, it is vital to address privacy and security concerns of both data and model together with other performance metrics when commercializing machine learning models. Our aim is to show that privacy-preserving machine learning inference methods can safeguard the intellectual property of models and prevent plaintext models from disclosing information about the sensitive data employed in training these ML models. Additionally, these methods protect the confidentiality of model users’ sensitive patient data. We accomplish this by performing a security analysis to determine an appropriate query limit for each user, using the European Spine Study Group’s (ESSG) adult spinal deformity dataset. We implement a privacy-preserving tree-based machine learning inference and run two security scenarios (scenario A and scenario B) containing four parts with progressively increasing the number of synthetic data points, which are used to enhance the accuracy of the attacker’s substitute model. A target model is generated with particular operation site(s) in each scenario, and substitute models are built with nine-time threefold cross-validation using the XGBoost algorithm with the remaining sites’ data to assess the security of the target model. First, we create box plots ofthe test sets’ accuracy, sensitivity, precision, and F-score metrics to compare the substitute models’ performance with the target model. Second, we compare the gain values of the target and substitute models’ features. Third, we provide an in-depth analysis to check the inclusion of target model split points in substitute mod","cbCaia8POHUzI3q1","https://ap.wps.com/l/cbCaia8POHUzI3q1","pdf",2661081,1,26,"English","en",105,"# Abstract\n# Introduction\n# Security analysis and query limits\n# Privacy-preserving tree-based inference\n## Attacker scenarios (A and B)\n# Evaluation and comparisons\n## Performance metrics\n## Feature gain and split-point heatmaps\n## Public vs privacy-preserving outputs and timing","[{\"question\":\"What problem does privacy-preserving ML inference address in this work?\",\"answer\":\"It aims to prevent released or inferred (plaintext) models from disclosing information about sensitive training data and to protect confidentiality of patient data used by model users.\"},{\"question\":\"How is the appropriate query limit determined?\",\"answer\":\"The paper performs a security analysis to establish an appropriate query limit for each user based on the European Spine Study Group adult spinal deformity dataset.\"},{\"question\":\"What comparison methods are used to evaluate the privacy-preserving model?\",\"answer\":\"The evaluation includes comparing substitute vs target model performance metrics, analyzing feature gain differences, using heatmaps to inspect inclusion of target split points, and contrasting outputs and intermediate timing between public and privacy-preserving models.\"}]","Privacy-Preserving Machine Learning (PPML) Inference for Clinically Actionable Models | PDF",1785730718,66,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"privacy-preserving-machine-learning-ppml-inference-for-clinically-actionable-models","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/privacy-preserving-machine-learning-ppml-inference-for-clinically-actionable-models/120574/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-03",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does privacy-preserving ML inference address in this work?","Question",{"text":75,"@type":76},"It aims to prevent released or inferred (plaintext) models from disclosing information about sensitive training data and to protect confidentiality of patient data used by model users.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How is the appropriate query limit determined?",{"text":80,"@type":76},"The paper performs a security analysis to establish an appropriate query limit for each user based on the European Spine Study Group adult spinal deformity dataset.",{"name":82,"@type":73,"acceptedAnswer":83},"What comparison methods are used to evaluate the privacy-preserving model?",{"text":84,"@type":76},"The evaluation includes comparing substitute vs target model performance metrics, analyzing feature gain differences, using heatmaps to inspect inclusion of target split points, and contrasting outputs and intermediate timing between public and privacy-preserving models.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]