MedPriv-Bench: Benchmarking the Privacy-Utility Trade-off of Large Language Models in Medical Open-End Question Answering
This paper introduces MedPriv-Bench, the first benchmark designed to jointly evaluate the privacy-utility trade-off in medical large language models by synthesizing realistic privacy threats and demonstrating a pervasive tension between clinical accuracy and patient data protection.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you hire a brilliant, super-smart medical assistant (an AI) to help you understand your health records. You want this assistant to be incredibly helpful, giving you the best possible advice based on your specific history. But there's a catch: you don't want it to accidentally spill your deepest secrets to the world while doing so.
This paper, MedPriv-Bench, is about building a "stress test" to see if these AI assistants can walk that tightrope between being helpful and being discreet.
Here is the breakdown in simple terms:
1. The Problem: The "Mosaic" Leak
Usually, we think of privacy leaks as the AI accidentally saying your name or your address. But this paper points out a sneakier danger called "Contextual Leakage."
The Analogy: Imagine you are in a crowded room. If someone shouts your name, everyone knows who you are (that's a standard leak). But what if no one says your name? Instead, someone describes you as: "A 55-year-old deep-sea welder who just had a rare stem cell transplant for a specific syndrome called VEXAS."
Even though they didn't say your name, that specific combination of details is like a unique fingerprint. Anyone who knows you could instantly figure out, "Oh, that's Bob!" The AI might not mean to reveal your identity, but by trying to give a perfectly detailed answer, it accidentally paints a picture that is too specific.
2. The Solution: A New "Stress Test" (MedPriv-Bench)
Before this paper, we had tests to see if AI doctors were smart enough to answer questions correctly. We didn't have a test to see if they were safe enough.
The authors built MedPriv-Bench, which is like a fire drill for medical AI.
- The Setup: They created a fake medical database.
- The Trap: They secretly injected "secret ingredients" into the patient files (like "the patient is homeless," "the patient is depressed," or "the patient is a celebrity").
- The Test: They asked the AI questions that needed those secrets to answer well, but didn't ask for the secrets directly.
- Example Question: "How should we plan this patient's discharge?"
- The Trap: To answer well, the AI needs to know the patient is homeless. But if it says "The patient is homeless," it has leaked the secret. If it says nothing, the advice might be bad.
3. The "Referee" (The NLI Judge)
How do you know if the AI leaked a secret? You can't ask a human to read thousands of answers. So, the authors created a digital referee.
The Analogy: Think of the referee as a detective with a magnifying glass.
- The AI gives an answer.
- The detective (a specialized computer program) asks: "Does this answer logically prove the secret exists?"
- If the AI says, "We need to find a shelter," the detective knows, "Aha! You figured out the patient is homeless, even though you didn't say the word 'homeless'."
- This referee is surprisingly good, agreeing with human experts about 86% of the time.
4. The Big Discovery: The "Helpful vs. Safe" Trade-off
The researchers tested 9 different AI models (some famous, some medical-specific). They found a universal rule: The smarter and more helpful the AI tries to be, the more likely it is to leak secrets.
The Analogy: Imagine a butler.
- The "Over-Reasoning" Butler: This butler is so eager to help that if you ask, "What should I wear?", he says, "Well, since you have a rash on your left arm and you're allergic to wool, and you're going to a wedding in July, you should wear a linen shirt." He is very helpful, but he also revealed you have a rash and an allergy (secrets you didn't ask to share).
- The "Safe" Butler: This butler says, "I'm not sure what to recommend without more info." He is safe, but not very helpful.
The paper found that medical-specific AIs (trained only on medical books) were better at keeping secrets than general AIs (like the ones that write emails and code). However, even the best ones struggled. When they tried to protect privacy, their answers became a bit less useful.
5. The Takeaway
The paper concludes that we can't just trust AI to "behave" in hospitals. We need a standard way to check them.
The Final Metaphor:
Think of medical AI like a new car. Before you let it drive your family, you don't just check if the engine is fast (Utility); you also check if the brakes work (Privacy).
- MedPriv-Bench is the new crash-test dummy and brake-test track specifically designed for medical cars.
- It shows us that right now, many of these "cars" are fast but have weak brakes. We need to fix the brakes (privacy) without slowing the engine down too much (utility), or we risk a crash.
In short: This paper gives us the tools to stop AI doctors from accidentally "telling on" their patients while trying to save them.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.