Privacy risks from medical AI tools are not shared equally

Nature作者:Haoran Zhang2026年8月4日正文已收录本站
  • NEWS AND VIEWS

Privacy attacks can reveal whether someone’s medical data was used to train an AI model. People who differ from the majority are the most vulnerable to such attacks.

By

  1. Haoran Zhang
    1. Haoran Zhang is in the Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, Massachusetts 02139, USA.

  2. Marzyeh Ghassemi
    1. Marzyeh Ghassemi is in the Department of Electrical Engineering and Computer Science, Massachusetts Institute of Technology, Cambridge, Massachusetts 02139, USA.

The use of artificial-intelligence tools in medicine has hinged on an implicit bargain. Patients and health systems permit sensitive records to be used for research, usually after de-identification so that names and other pieces of personal information are removed. In return, researchers and developers create tools that could improve health care, for example by enabling earlier diagnoses and new treatments. This bargain relies on the assumption that it is impossible for people who have access to an AI model to infer information about individuals whose data were used to train it. Writing in Nature, Knolle et al.1 show that, in the context of powerful machine-learning models, this assumption is often untrue.

Nature 656, 42-44 (2026)

doi: https://doi.org/10.1038/d41586-026-02288-9

References

  1. Knolle, M. A. et al. Nature 656, 192–198 (2026).

    Article  Google Scholar 

  2. Feldman, V. & Chiyuan, Z. In Proc. 34 Int. Conf. Neural Inf. Process. Syst. (eds Larochelle, H. et al.) 2881–2891 (Curran Associates, 2020).

  3. Tonekaboni, S., Stempfle, L., Fallahpour, A., Gerych, W. & Ghassemi, M. In Adv. Neural Inf. Process. Syst. 39 (eds Belgrave, D. et al.) 10555–10580 (2026).

  4. Geiping, J., Bauermeister, H., Dröge, H. & Moeller, M. In Proc. 34 Int. Conf. Neural Inf. Process. Syst. (eds Larochelle, H. et al.) 16937–16947 (Curran Associates, 2020).

  5. Chen, M. et al. In Proc. 2021 ACM SIGSAC Conf. Comput. Commun. Secur. 896–911 (ACM, 2021).

  6. Shokri, R., Stronati, M., Song, C. & Shmatikov, V. In Proc. 2017 IEEE Symp. Secur. Priv. (ed. O’Conner, L.) 3–18 (IEEE, 2017).

  7. Nissenbaum, H. Wash. Law Rev. 79, 119–157 (2004).

    Google Scholar 

  8. Gichoya, J. W. et al. Lancet Digit. Health 4, E406–E414 (2022).

    Article  PubMed  Google Scholar 

  9. Abadi, M. et al. In Proc. 2016 ACM SIGSAC Conf. Comput. Commun. Secur. 308–318 (ACM, 2016).

  10. Suriyakumar, V. M., Papernot, N., Goldenberg, A. & Ghassemi, M. In Proc. 2021 ACM Conf. Fairness Account. Transpar. 723–734 (ACM, 2021).

Download references

Competing Interests

The authors declare no competing interests.

  • Read the paper: Disparate privacy risks from medical AI

  • People are turning to AI chatbots to plug gaps in health information

  • A hidden predictor of sudden cardiac death uncovered by deep learning

  • See all News & Views

Subjects

Latest on:

  • Machine learning
  • Society
  • Health care
  • AI agents are checking the scientific literature — and spotting decades-old errors

    News

  • The Virtual Tissues foundation model resolves spatial proteomics across scales

    Article

  • Want to get more from AI? Treat every prompt like an experiment

    Career Column

  • Scientists don’t need more trust, they need public allies

    Correspondence

  • How I use statistics and my law degree to fight human-rights abuses

    Career Feature

  • New-deal mortgage programmes benefited white borrowers disproportionately

    Article

  • Heatwaves have killed millions. Here’s how scientists tally lives lost

    News Explainer

  • Put health systems at the centre of European heatwave plans

    Correspondence

  • Why the need for the WHO has never been greater

    World View