- NEWS AND VIEWS
Privacy attacks can reveal whether someone’s medical data was used to train an AI model. People who differ from the majority are the most vulnerable to such attacks.
By
-
Haoran Zhang
-
Haoran Zhang is in the Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, Massachusetts 02139, USA.
-
-
Marzyeh Ghassemi
-
Marzyeh Ghassemi is in the Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, Massachusetts 02139, USA.
-
The use of artificial-intelligence tools in medicine has hinged on an implicit bargain. Patients and health systems permit sensitive records to be used for research, usually after de-identification so that names and other pieces of personal information are removed. In return, researchers and developers create tools that could improve health care, for example by enabling earlier diagnoses and new treatments. This bargain relies on the assumption that it is impossible for people who have access to an AI model to infer information about individuals whose data were used to train it. Writing in Nature, Knolle et al.1 show that, in the context of powerful machine-learning models, this assumption is often untrue.
Nature 656, 42-44 (2026)
doi: https://doi.org/10.1038/d41586-026-02288-9
References
Knolle, M. A. et al. Nature 656, 192–198 (2026).
Article Google Scholar
Feldman, V. & Chiyuan, Z. In Proc. 34 Int. Conf. Neural Inf. Process. Syst. (eds Larochelle, H. et al.) 2881–2891 (Curran Associates, 2020).
Tonekaboni, S., Stempfle, L., Fallahpour, A., Gerych, W. & Ghassemi, M. In Adv. Neural Inf. Process. Syst. 39 (eds Belgrave, D. et al.) 10555–10580 (2026).
Geiping, J., Bauermeister, H., Dröge, H. & Moeller, M. In Proc. 34 Int. Conf. Neural Inf. Process. Syst. (eds Larochelle, H. et al.) 16937–16947 (Curran Associates, 2020).
Chen, M. et al. In Proc. 2021 ACM SIGSAC Conf. Comput. Commun. Secur. 896–911 (ACM, 2021).
Shokri, R., Stronati, M., Song, C. & Shmatikov, V. In Proc. 2017 IEEE Symp. Secur. Priv. (ed. O’Conner, L.) 3–18 (IEEE, 2017).
Nissenbaum, H. Wash. Law Rev. 79, 119–157 (2004).
Google Scholar
Gichoya, J. W. et al. Lancet Digit. Health 4, E406–E414 (2022).
Article PubMed Google Scholar
Abadi, M. et al. In Proc. 2016 ACM SIGSAC Conf. Comput. Commun. Secur. 308–318 (ACM, 2016).
Suriyakumar, V. M., Papernot, N., Goldenberg, A. & Ghassemi, M. In Proc. 2021 ACM Conf. Fairness Account. Transpar. 723–734 (ACM, 2021).
Download references
Competing Interests
The authors declare no competing interests.
Related Articles
-
Read the paper: Disparate privacy risks from medical AI
-
People are turning to AI chatbots to plug gaps in health information
-
A hidden predictor of sudden cardiac death uncovered by deep learning
-
See all News & Views
Subjects
Latest on:
- Machine learning
- Society
- Health care
-
AI agents are checking the scientific literature — and spotting decades-old errors
News
-
The Virtual Tissues foundation model resolves spatial proteomics across scales
Article
-
Want to get more from AI? Treat every prompt like an experiment
Career Column
-
Scientists don’t need more trust, they need public allies
Correspondence
-
How I use statistics and my law degree to fight human-rights abuses
Career Feature
-
New-deal mortgage programmes benefited white borrowers disproportionately
Article
-
Heatwaves have killed millions. Here’s how scientists tally lives lost
News Explainer
-
Put health systems at the centre of European heatwave plans
Correspondence
-
Why the need for the WHO has never been greater
World View