A learning rate adaptive medical image recognition method based on differential privacy
By employing a personalized cloud model and a differential privacy approach with adaptive learning rate adjustment, the problems of data silos and privacy leaks in federated learning are solved, enabling data fusion and privacy protection in medical image recognition, and improving the model's adaptability and accuracy.
Patent Information
- Application Number
- CN202311104879.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-30
- Publication Date
- 2025-11-04
- Estimated Expiration
- 2043-08-30
AI Technical Summary
In the Internet of Things (IoT) for healthcare, the problems of data silos and privacy breaches in federated learning have not been effectively resolved. In particular, the differences in data distribution and privacy protection needs among different medical institutions mean that a unified privacy budget cannot meet actual needs.
We employ a learning rate adaptive method based on differential privacy, combining a personalized cloud model and adaptive learning rate adjustment with deep convolutional neural networks and personalized privacy protection to achieve multi-institutional data fusion and privacy protection.
It enables data fusion among different medical institutions, improves the robustness of the model and the personalized adaptability of privacy protection, alleviates the differences in data distribution and privacy protection needs, and improves the accuracy and efficiency of medical image recognition.
Smart Images

Figure CN117079087B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to a learning rate adaptive medical image recognition method based on differential privacy, belonging to the technical field of medical image recognition. BACKGROUND
[0002] In today's digital age, the Internet of Medical Things (IoMTs) has become an important part of the medical field. The Internet of Medical Things plays an important role in medical image recognition, connecting sensors, devices and networks to exchange data and work together between medical devices and systems.
[0003] In the Internet of Medical Things, federated learning can be applied to timely detect changes in patient conditions, thereby supporting decision-making and resource allocation. Specifically, if a cancer patient goes to a hospital for treatment, the patient's condition can be determined by existing cancer data to support decision-making and resource allocation. However, the medical data of a hospital may not be sufficient to make accurate judgments, and the medical data of multiple hospitals needs to be combined.
[0004] However, these medical data are often distributed among various medical institutions, forming data silos. Federated learning can use cancer data from multiple hospitals to train decision-making models. Thus, federated learning provides more comprehensive information support and more accurate decision-making models, thereby improving the efficiency and accuracy of emergency decision-making.
[0005] Although federated learning solves the problem of data silos, federated learning uploads the model of each vehicle terminal, which carries personal privacy. Attackers can still leak privacy information by analyzing the parameters in model training, such as the weights of deep neural network training.
[0006] To address this issue, some scholars have proposed a federated learning algorithm based on differential privacy, which adds random noise to the model parameters uploaded to the server, thereby ensuring data privacy. Therefore, the federated learning algorithm based on differential privacy has obvious lightweight advantages, better applicability and practicality.
[0007] However, the federated learning algorithm based on differential privacy uniformly allocates privacy budgets to each client. However, in the medical application scenario, the geographical distribution of medical institutions is different, the population distribution of patients is different, and the privacy protection requirements of each institution are different. Therefore, the assumption of uniform allocation of privacy budgets is unrealistic and cannot be implemented. SUMMARY
[0008] The present application aims to overcome the deficiencies in the prior art, and provide a learning rate adaptive medical image recognition method based on differential privacy, which can realize data fusion of multiple medical institutions and achieve the effect of personalized privacy protection.
[0009] To achieve the above object, the present application is implemented by the following technical scheme: a learning rate adaptive medical image recognition method based on differential privacy, comprising the following steps,
[0010] Collecting medical images of patient lesion sites;
[0011] Inputting the collected medical images into a local model pre-installed in the local client and fused with medical data of multiple hospitals, and outputting the recognition result.
[0012] Further, the construction method of the local model fused with medical data of multiple hospitals comprises:
[0013] a. Multiple clients construct a local model, set the hyperparameters and loss function of the local model;
[0014] b. The client transmits the local model to the server;
[0015] c. The server obtains the local model of each client, aggregates and maintains the local model of each client, and generates a personalized cloud model for each client;
[0016] d. The server transmits the personalized cloud model to the corresponding clients;
[0017] e. The client obtains local data and a personalized cloud model, takes the personalized cloud model as the adjacent center of the proximal term of the loss function, trains the local model using the loss function and the local data until the training times reach the local iteration times, and obtains the trained local model;
[0018] f. Repeat steps b-e until the training times reach the global iteration times, and output the local model.
[0019] Further, the local model adopts a deep convolutional neural network, the deep convolutional neural network adopts a RELU function as an activation function, and is composed of 2 convolutional layers, 2 pooling layers, 1 dropout layer, 3 batch processing layers and 2 fully connected layers, and the convolution kernel size of the convolutional layer is 5.
[0020] The hyperparameters of the local model include local batch size, local iteration times, global iteration times, client number, client selection ratio value of each round, global privacy budget, differential privacy relaxation, gradient clipping threshold and algorithm learning rate.
[0021] Further, the loss function adopts a minimum loss function, and the minimum loss function is composed of a cross-entropy loss function and an attention inducing function;
[0022] The cross-entropy loss function is used to determine the closeness of the model output result to the correct output value.
[0023] The attention inducing function is used to repeatedly encourage similar clients to cooperate more to adaptively promote potential pairwise cooperation between clients.
[0024] The expression of the minimum loss function is:
[0025]
[0026] Wherein, The minimum loss function is represented by W = [w1,..., w K ], and λ is a regularization parameter, λ > 0.
[0027] The cross-entropy loss function is represented by k, which represents the kth client, K represents the number of clients, L k is the loss function of the kth client, w k is the local model parameter of the kth client.
[0028] The attention inducing function is represented by A, which represents a negative exponential function, j represents the jth client, and w j is the local model parameter of the jth client.
[0029] Further, the server obtains the local model of each client, aggregates and maintains the local model of each client, and generates a personalized cloud model for each client, including:
[0030] The server obtains the local model of each client.
[0031] In the tth iteration, the attention inducing function A(W) in the local model loss function is optimized by gradient descent, and the personalized cloud model parameter of the tth iteration is obtained, and the expression is as follows:
[0032]
[0033] Wherein, U t is the personalized cloud model parameter of the tth iteration, represents derivation, W t-1 is the local model parameter of the t-1th iteration, and α t is the algorithm learning rate of the tth iteration.
[0034] The local model of all clients is linearly combined to generate the personalized cloud model of each client, and the expression is as follows:
[0035]
[0036] wherein, is the personalized cloud model parameter of the kth client in the tth iteration, is the local model parameter of the kth client in the (t-1)th iteration, is the local model parameter of the jth client in the (t-1)th iteration, A'(||w k -w j || 2 ) represents the derivative of A(||w k -w j || 2 ), is the local model parameter set, ξ k,1 , …, ξ k,K is the linear combination weight of ;
[0037] The generated personalized cloud model is initialized.
[0038] Further, the client obtains the local image data and the personalized cloud model, uses the personalized cloud model as the adjacent center of the proximal term of the loss function, trains the local model by using the loss function and the local image data until the training times reach the local iteration times, and obtains the trained local model, including:
[0039] The client obtains the personalized cloud model;
[0040] The personalized cloud model parameter is used as the adjacent center, that is, U t is used instead of the proximal term W j in the minimum loss function, and the local model is trained, and the expression is as follows:
[0041]
[0042] wherein, U t is the personalized cloud model parameter, W t is the local model parameter in the tth iteration, represents the minimum loss function, represents the minimum cross-entropy loss function, λ is a regularization parameter, λ>0, α t is the algorithm learning rate in the tth iteration, and W is the local model parameter;
[0043] Repeat the above training process until the number of training reaches the local iteration number, and get the trained local model.
[0044] Further, the client adjusts the algorithm learning rate, specifically:
[0045] The client first randomly samples the local image data samples to obtain the current algorithm learning rate;
[0046] Using the sampled data, the local model is continuously executed twice gradient clipping and gradient descent with a step size of half the current learning rate, obtaining two half-step gradient matrices;
[0047] Using the sampled data, the local model is continuously executed twice gradient clipping and gradient descent with a step size of half the current learning rate, obtaining two half-step gradient matrices;
[0048] The gradient error between the gradient matrix of the local model and the two half-step gradient matrices is evaluated; the algorithm learning rate is adjusted according to the gradient error, expressed as follows:
[0049]
[0050] Where, err t is the gradient error, ψ is the gradient error pre-value, α min <1, α max >1.
[0051] Further, the local image data needs to be standardized, and the standardization includes:
[0052] Convert the local image data into an image matrix;
[0053] Standardize the image matrix channel by channel, the image matrix mean value becomes 0, the image matrix standard deviation becomes 1, and the elements of the image matrix are within the range [-1, 1], expressed as follows:
[0054]
[0055] Where, channel is the number of image matrix channels, input[channel] is the input image matrix, mean[channel] is the image matrix mean value, std[channel] is the image matrix standard deviation, and output[channel] is the output image matrix.
[0056] Further, the local model is personalized and privacy protected according to the privacy preference set by the client, specifically:
[0057] Obtain the current local model parameters, and the client adjusts the local model parameters according to the privacy protection level ε k, a Gaussian noise is generated and added to the local model parameters, and the expression is as follows:
[0058] M=f(D)+N(0,cDeltaf / epsilon)
[0059] Wherein, M is the local model parameter after adding noise, f(D) is the local model parameter before adding noise, Deltaf is the sensitivity, the value is f(D') is the local model parameter of the adjacent data set trained without adding noise, c is a constant, the value range is
[0060] Further, the privacy protection level epsilon k Including three, it is expressed as epsilon(epsilon low , epsilon mid , epsilon high ), the privacy protection level epsilon k It is determined by the privacy preference set by the client.
[0061] Compared with the prior art, the beneficial effects achieved by the present application are:
[0062] The present application can adaptively promote potential pairwise collaboration between customers by repeatedly encouraging similar customers to collaborate more. Thus, the problem of different medical institution data not being independent and identically distributed is alleviated.
[0063] Traditional fixed learning rate may not be well adapted to the needs of different data distributions, model complexity and training stages. Therefore, the traditional fixed learning rate may not perform well for different data distributions and noise. The present application can dynamically adjust the learning rate according to the characteristics of the actual data through the learning rate adaptive algorithm, thereby improving the robustness of the model for different data distributions.
[0064] In medical application scenarios, there are differences in geographical distribution, patient population distribution and privacy protection requirements of different medical institutions. However, the traditional federated learning algorithm based on differential privacy adopts the assumption of uniform allocation of privacy budget, which cannot practically meet the actual needs and privacy protection requirements of each institution. In addition, the uniform privacy budget level means that some customers will waste a lot of privacy budget. The present application can protect information according to the privacy preference set by the user through personalized differential privacy, achieving the purpose of personalized privacy protection. BRIEF DESCRIPTION OF DRAWINGS
[0065] Figure 1 is a flowchart of a differential privacy-based learning rate adaptive medical image recognition method according to an embodiment of the present application;
[0066] Figure 2A learning rate adaptive module flowchart of a learning rate adaptive medical image recognition method based on differential privacy in an embodiment of the present application is shown in the figure.
[0067] Figure 3 A personalized differential privacy flowchart of a learning rate adaptive medical image recognition method based on differential privacy in an embodiment of the present application is shown in the figure. DETAILED DESCRIPTION
[0068] The present application will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present application, and cannot be used to limit the protection scope of the present application.
[0069] The embodiment of the present application provides a learning rate adaptive medical image recognition method based on differential privacy. In the embodiment, the local data is a rectal cancer image data set, and the data comes from the PathMNIST data set of the MedMNIST data set collection. By recognizing the rectal cancer image, the survival condition of the rectal cancer histological section is predicted.
[0070] The recognition method comprises the following steps:
[0071] Collecting a medical image of a lesion part of a patient;
[0072] Inputting the collected medical image into a local model pre-installed in a local client and fused with medical data of multiple hospitals, and outputting a recognition result.
[0073] As shown in the figure, the construction method of the local model fused with the medical data of multiple hospitals comprises: Figure 1
[0074] S1, the client builds a local model and sets a loss function and hyperparameters:
[0075] The client builds a local model, and all clients use a local model with the same structure. The local model adopts a deep convolutional neural network, and the deep convolutional neural network model adopts an SGD optimizer, which is composed of 2 convolutional layers, 2 pooling layers, 1 dropout layer, 3 batch processing layers and 2 fully connected layers, wherein each convolution kernel size is 5, and a ReLU function is used as an activation function.
[0076] The hyperparameter setting is specifically: the local batch size is set to 40, the local iteration number is 5, the global iteration number is 100, the number of clients is 50, the value of the client selection ratio of each round is 0.3, the global privacy budget is 50, the relaxation degree of differential privacy is 1 / 6000, the gradient clipping threshold is 1, and the learning rate is 0.005.
[0077] The loss function adopts a minimum loss function, which is composed of a cross-entropy loss function and an attention inducing function.
[0078] The cross-entropy loss function is the sum of the training losses of the local models of all clients, which is used to determine the closeness of the output results of the model to the correct output values, and this part allows each client to train its own local model independently using its own private training data.
[0079] The attention inducing function can repeatedly encourage similar clients to cooperate more and adaptively promote potential pairwise cooperation between clients, which is a negative exponential function with a hyperparameter
[0080] The expression of the minimum loss function is as follows:
[0081]
[0082] wherein, represents the minimum loss function, W = [w1,..., w K ], λ is a regularization parameter, λ > 0;
[0083] represents the cross-entropy loss function, k represents the kth client, K is the number of clients, L k is the loss function of the kth client, w k is the local model parameter of the kth client;
[0084] represents the attention inducing function, A represents the negative exponential function, j represents the jth client, w j is the local model parameter of the jth client.
[0085] S2, the server generates a personalized cloud model for each client:
[0086] The client transmits the built local model to the server, and the server obtains the local model of each client.
[0087] In the tth iteration, the attention inducing function A(W) in the local model loss function is optimized by gradient descent, and the personalized cloud model parameter of the tth iteration is obtained, and the expression is as follows:
[0088]
[0089] wherein, U t is the personalized cloud model parameter of the tth iteration, represents derivation, W t-1 is the local model parameter of the t-1th iteration, and αt is the algorithm learning rate for the tth iteration.
[0090] The local model of all clients is linearly combined to generate the personalized cloud model of each client, and the expression is as follows:
[0091]
[0092] wherein, is the personalized cloud model parameter of the kth client in the tth iteration, is the local model parameter of the kth client in the t-1th iteration, is the local model parameter of the jth client in the t-1th iteration, A'(||w k -w j || 2 ) represents the derivative of A(||w k -w j || 2 ), is the local model parameter set, and ξ k,1 , …, ξ k,K is the linear combination weight of ;
[0093] The generated personalized cloud model is initialized.
[0094] In medical applications, to achieve personalized federated learning and protect privacy, the server initializes a personalized cloud model for each participating client, and the cloud model is maintained by the server. By initializing the personalized cloud model, an initial state of the model that is targeted for each client can be provided to better adapt to the specific data and needs of the client.
[0095] S3, the client standardizes the local image data:
[0096] The local image data is collected, loaded into the algorithm as an image matrix, and then the image is standardized channel by channel. The average value of the image matrix becomes 0, and the standard deviation of the image matrix becomes 1, so that the elements of the image matrix are within the range of [-1, 1], and the expression is as follows:
[0097]
[0098] wherein, channel is the number of image matrix channels, input[channel] is the input image matrix, mean[channel] is the average value of the image matrix, std[channel] is the standard deviation of the image matrix, and output[channel] is the output image matrix.
[0099] Standardization ensures good network convergence. Before the relative importance of each dimension (RDB channel number, width, height) is known, standardization makes the distribution of each dimension of the input image similar, thus allowing the same learning rate, regularization coefficient, weight initialization, and activation function to be set for each dimension during network training.
[0100] S4. Client-side training of local model:
[0101] S4-1, The client obtains the personalized cloud model.
[0102] Using personalized cloud model parameters as proximity centers, i.e., using U t Replace the proximal term W in the minimum loss function j The local model is trained until the number of training iterations reaches the local iteration count, resulting in a well-trained local model.
[0103] The training expression is as follows:
[0104]
[0105] Among them, U t For personalized cloud model parameters, W t Let be the local model parameters for the t-th iteration. Describes the minimum loss function. Let λ represent the minimum cross-entropy loss function, where λ is the regularization parameter, λ > 0, and α t Let W be the learning rate of the algorithm in the t-th iteration, and W be the local model parameters.
[0106] The calculation is obtained through the following formula:
[0107]
[0108] S4-2. The client uses the learning rate adaptive module to adjust the learning rate:
[0109] like Figure 2 As shown, the client first randomly samples local data samples and obtains the latest learning rate. Then, it uses the sampled data to train the local model and obtains the gradient matrix of the current local model.
[0110] Since the personalized differential privacy module needs to add noise to the local model, which may cause gradient explosion, the obtained gradient matrix is clipped before adding noise. Specifically, the local model is subjected to gradient clipping and gradient descent twice with a step size of half the current learning rate using the sampled data, resulting in two gradient matrices with half the step size.
[0111] The gradient matrix of a complete step is obtained by gradient clipping and gradient descent of the current complete learning rate of the local model using the sampling data, and then the local model is updated.
[0112] The gradient error between the gradient matrix of a complete step and the gradient matrix of two half steps is evaluated, and the step of the learning rate is adjusted according to the gradient error, and the expression of the step of the learning rate is as follows:
[0113]
[0114] Where, err t is the gradient error, ψ is the gradient error pre-value, α min < 1, α max > 1, and in this embodiment, α min = 0.9, α max = 1.1.
[0115] S4-3, the personalized differential privacy module can protect information according to the privacy preference set by the user, so as to achieve the purpose of personalized privacy protection.
[0116] As shown in Figure 3 , the specific steps of the personalized differential privacy module are given:
[0117] The current local model parameters are obtained, and the client generates Gaussian noise according to the privacy protection level ε k and adds it to the parameters of the local model, and sends it to the server.
[0118] The noise mechanism is a Gaussian noise mechanism suitable for numerical data, and its expression is as follows:
[0119] M = f(D) + N(0, cΔf / ε) (6)
[0120] Where, M is the model parameter after adding noise, f(D) is the model parameter before adding noise, Δf is the sensitivity, and the value is f(D') is the local model parameter of the adjacent data set without adding noise, c is a constant, and the value range is
[0121] The privacy protection budget is divided into three levels, which can be represented as ε(ε low , ε mid , ε high ), and the strength of privacy protection increases with the increase of the level, and the privacy protection level ε k is determined by the privacy budget level selected by the user, which determines the addition of local noise.
[0122] For a client k, if a random algorithm M outputs the same result D* under any two pieces of data D and D', that is, formula (7) is satisfied, it is said that M satisfies ε-differential privacy, and formula (7) is as follows:
[0123]
[0124] Here, Pr can be expressed as a probability density function of a Gaussian distribution, because the algorithm uses a Gaussian mechanism.
[0125] S5, repeating steps S2-S4 until the training number reaches the global iteration number, outputting the local model. The above is only the preferred embodiment of the present application, it should be pointed out that, for those skilled in the technical field, without departing from the technical principles of the present application, can make a number of improvements and deformation, these improvements and deformation also should be considered as the protection scope of the present application.
Claims
1. A learning rate adaptive medical image recognition method based on differential privacy, characterized in that, Includes the following steps: Acquire medical images of the patient's lesion site; The acquired medical images are input into a local model that integrates medical data from multiple hospitals and is pre-set in the local client, and the recognition results are output. Methods for building local models that integrate medical data from multiple hospitals include: a. The client builds a local model and sets the hyperparameters and loss function of the local model; b. The client transfers the local model to the server; c. The server obtains the local models of each client, aggregates and maintains the local models of each client, and then generates a personalized cloud model for each client. d. The server transmits the personalized cloud model to the corresponding clients; e. The client acquires local data and a personalized cloud model, using the personalized cloud model as the nearest neighbor center of the near term in the loss function. The local model is then trained using the loss function and local data until the training iterations reach the required number of iterations, resulting in a trained local model, including: The client obtains a personalized cloud model; Using personalized cloud model parameters as proximity centers, i.e. Replace the proximal term in the minimum loss function The local model is trained using the following expression: ; in, For personalized cloud model parameters, , For the first Local model parameters for the next iteration , Describes the minimum loss function. This represents the minimum cross-entropy loss function. For regularization parameters, , For the first Learning rate of the algorithm in each iteration For local model parameters; Repeat the above training process until the number of training iterations reaches the local iteration count, and you will get a trained local model. This also includes client-side adjustments to the algorithm's learning rate, specifically: The client randomly samples local image data to obtain the current algorithm learning rate. Using the sampled data, perform gradient clipping and gradient descent twice on the local model with a step size of half the current learning rate to obtain two gradient matrices with half the step size. The local model is subjected to gradient clipping and gradient descent at the current full learning rate using the sampled data to obtain the gradient matrix of the full step size, and then the local model is updated. Evaluate the gradient matrix of the local model and the gradient error between the two half-step gradient matrices; The learning rate of the algorithm is adjusted based on the gradient error, as expressed below: ; in, For gradient error, This is the gradient error prediction value. , ; f. Repeat steps b to e until the number of training iterations reaches the global iteration count, and output a local model that integrates medical data from multiple hospitals.
2. The learning rate adaptive medical image recognition method based on differential privacy according to claim 1, characterized in that, The local model employs a deep convolutional neural network, which uses the ReLU function as the activation function. It consists of two convolutional layers, two pooling layers, one dropout layer, three batch processing layers, and two fully connected layers. The kernel size of the convolutional layers is 5. The hyperparameters of the local model include local batch size, local iteration count, global iteration count, number of clients, client selection ratio per round, global privacy budget, differential privacy relaxation, gradient pruning threshold, and algorithm learning rate.
3. The learning rate adaptive medical image recognition method based on differential privacy according to claim 1, characterized in that, The loss function is the minimum loss function, which consists of the cross-entropy loss function and the attention-induced function. The cross-entropy loss function is used to determine how close the model's output is to the correct output value; Attention-inducing functions are used to repeatedly encourage similar clients to collaborate more, thereby adaptively promoting potential pairwise collaboration among clients; The expression for the minimum loss function is: ; in, Describes the minimum loss function. , For regularization parameters, ; Represents the cross-entropy loss function. Indicates the first One client, For the number of clients, For the first Loss function for each client, For the first Local model parameters for each client; Represents the attention-inducing function. This represents a negative exponential function. Indicates the first One client, For the first Local model parameters for each client.
4. The learning rate adaptive medical image recognition method based on differential privacy according to claim 1, characterized in that, The server retrieves the local models from each client, aggregates and maintains these local models, and then generates a personalized cloud model for each client, including: The server retrieves the local models from each client; In the In this iteration, the attention-induced function in the local model's loss function is adjusted using gradient descent. Optimize to obtain the first The personalized cloud model parameters for the next iteration are expressed as follows: ; in, For the first The parameters of the personalized cloud model in the next iteration. To express differentiation, For the first Local model parameters for the next iteration For the first The algorithm's learning rate for each iteration; A linear combination operation is performed on the local models of all clients to generate a personalized cloud model for each client, as shown in the following expression: ; in, For the first In the nth iteration Personalized cloud model parameters for each client For the first In the nth iteration Local model parameters for each client. For the first In the nth iteration Local model parameters for each client. express The derivative of For the local model parameter set, for The linear combination weights; Initialize the generated personalized cloud model.
5. The learning rate adaptive medical image recognition method based on differential privacy according to claim 1, characterized in that, The local image data needs to be standardized, and the standardization process includes: Convert local image data into an image matrix; The image matrix is standardized channel by channel, so that the mean of the image matrix becomes 0 and the standard deviation of the image matrix becomes 1, making all elements of the image matrix fall within the range of [-1, 1]. The expression is as follows: ; Where channel is the number of channels in the image matrix, input[channel] is the input image matrix, mean[channel] is the mean value of the image matrix, std[channel] is the standard deviation of the image matrix, and output[channel] is the output image matrix.
6. The learning rate adaptive medical image recognition method based on differential privacy according to claim 1, characterized in that, This also includes personalized privacy protection for local models based on the privacy preferences set by the client, specifically: The client obtains the current local model parameters based on the privacy protection level. This generates Gaussian noise, which is then added to the local model parameters, as shown in the following expression: ; in, These are the parameters of the local model after adding noise. These are the local model parameters before adding noise. For sensitivity, the value is [value to be filled in]. , The parameters of a local model trained on neighboring datasets without added noise. It is a constant, and its range is [value range missing]. .
7. The learning rate adaptive medical image recognition method based on differential privacy according to claim 6, characterized in that, The privacy protection level It includes three, which are represented as follows: Privacy protection level It is determined by the privacy preferences set in the client settings.