Medical image privacy protection method and system with adjustable protection level

By combining a medical identity recognition network with the minimum description length principle, and using a diffusion model to fuse identity information masking with diagnostic semantic information, the problem of balancing medical image privacy protection and diagnostic performance is solved, achieving flexible privacy protection and retention of key information.

CN120823099APending Publication Date: 2025-10-21SHANGHAI JIAOTONG UNIV
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510929854.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-10-21

AI Technical Summary

Technical Problem

Existing medical image de-identification technologies struggle to balance privacy protection and diagnostic performance. Conventional methods destroy diagnostic information, while generative adversarial networks pose a risk of leaving identity clues and lack flexibility.

Method used

A medical identity recognition network is used to generate identity similarity heatmaps. Combined with a feature separation strategy based on the minimum description length principle, an identity information masking image and diagnostic semantic information are fused through a diffusion model to generate de-identified images that meet privacy protection requirements.

Benefits of technology

It enables flexible masking of identity information under different privacy protection levels, while retaining diagnostic information to the maximum extent, thereby improving the practicality and privacy security of the images.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120823099A_ABST
    Figure CN120823099A_ABST
Patent Text Reader

Abstract

The invention provides a protection-level-adjustable medical image privacy protection method and system, and the method comprises the steps: carrying out the local feature extraction of an original image through a medical identity recognition network based on a visual converter, and generating an identity similarity heat map; performing binarization processing on the identity similarity heat map by setting an adjustable threshold value to realize identity information shielding images under different privacy protection levels; the method comprises the following steps: extracting diagnosis semantic information in an original image by means of a pre-trained medical basic model, and stripping residual identity information by adopting a feature separation strategy constructed by a minimum description length principle; through an image synthesis mode based on a diffusion model, an identity information shielding image and compensated semantic information are fused, and a de-identity image which not only meets privacy protection requirements but also retains clinical information is generated. According to the method, the identity information of the patient in the medical image is effectively hidden, and meanwhile, the completeness of the diagnostic information required by the downstream medical task is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of image processing technology, and in particular, to a medical image privacy protection method and system with adjustable protection levels. Background Art

[0002] With the rapid development of digital medicine, large-scale medical imaging has become crucial for computer-assisted diagnosis (CAD), but the associated risk of patient re-identification has also become increasingly prominent. When hospitals collect medical images such as X-rays, CT scans, and MRIs, they not only need to accurately capture critical diagnostic information but also face the risk of identity leakage due to the inherent anatomical features in the images. Once this image data is obtained by unauthorized individuals, re-identification technology can be used to recover the patient's identity, leading to privacy breaches and security risks. Therefore, effectively concealing identity information in images while preserving the meaning of medical diagnostics has become a key technical challenge that needs to be addressed.

[0003] Existing medical image de-identification technologies have several drawbacks. Primarily, conventional image processing methods such as blurring, pixelation, or noise injection not only weaken identity features but also severely damage subtle lesion information in the image that is closely related to clinical diagnosis, significantly reducing the image's practicality in subsequent detection and segmentation tasks.

[0004] Secondly, most methods lack flexibility in privacy protection and cannot achieve adjustable privacy shielding effects for different application scenarios, resulting in a sharp decrease in diagnostic performance at high protection levels.

[0005] In addition, even if generative adversarial networks or conditional generative models are used for de-identification, weak identity clues may still remain in the processed image, posing the risk of reverse inference to restore the original identity.

[0006] A Chinese patent application numbered 202410534441.3, which was retrieved, discloses a privacy-preserving medical image processing method. The method first extracts and enhances image features, then inputs the image features corresponding to the enhanced medical image data into a desensitization model to obtain desensitized medical image data. The desensitized medical image data is then subjected to privacy data stripping verification, and the desensitized medical image data is output when the verification passes. However, weak identity clues may still remain in the processed image, posing a risk of reverse inference and restoration of the original identity. Summary of the Invention

[0007] In response to one of the deficiencies in the prior art, the present application aims to provide a medical image privacy protection method and system with adjustable protection levels.

[0008] In a first aspect of the present application, a medical image privacy protection method with adjustable protection level is provided, comprising:

[0009] Using a medical identity recognition network to extract local features from the original image and generate an identity similarity heat map; binarizing the identity similarity heat map by setting an adjustable threshold to obtain an identity information masked image that meets the privacy protection level;

[0010] Extracting diagnostic semantic information from the original image using a medical basic model, and adopting a feature separation strategy based on a minimum description length principle to strip away residual identity information and obtain diagnostic semantic information with a minimum description length;

[0011] Through an image synthesis method based on a diffusion model, the identity information masked image is fused with diagnostic semantic information of minimum description length to generate a de-identified image that meets privacy protection requirements while retaining clinical information.

[0012] Optionally, the method of extracting local features from the original image using a medical identity recognition network and generating an identity similarity heat map; and binarizing the identity similarity heat map by setting an adjustable threshold to obtain an identity information masked image that meets the privacy protection level, includes:

[0013] Using a pre-trained medical identity recognition network to extract local features from the original image to obtain a feature tensor;

[0014] Performing spatial average pooling on the feature tensor to obtain a global identity embedding vector;

[0015] calculating the cosine similarity between each local position in the feature tensor and the global identity embedding vector to generate a similarity graph;

[0016] According to the privacy protection level requirement, an adjustable threshold is selected to perform binarization processing on the similarity graph to obtain an identity clue binarization graph;

[0017] The identity clue binarized image is adjusted to the same spatial resolution as the original image using nearest neighbor upsampling, and an identity information masked image is obtained through an element-by-element multiplication operation.

[0018] Optionally, the step of selecting an adjustable threshold value to perform binarization processing on the similarity graph according to the privacy protection level requirement to obtain the identity clue binarization graph includes:

[0019] Privacy protection levels include 5% identification rate, 10% identification rate, and 20% identification rate;

[0020] The corresponding thresholds are 95%, 90%, and 80% areas of the similarity graph, respectively;

[0021] Select the privacy protection level according to your needs and determine the corresponding threshold;

[0022] The similarity graph is binarized according to a determined threshold value to obtain an identity clue binarized graph.

[0023] Optionally, extracting the diagnostic semantic information from the original image using a medical basic model and adopting a feature separation strategy based on a minimum description length principle to strip away residual identity information to obtain diagnostic semantic information with a minimum description length includes:

[0024] extracting medical features from the original image using a pre-trained medical basic model to obtain original medical semantic information;

[0025] Mapping the original medical semantic information into a latent discrete code space using an encoder network based on a three-layer convolution operation to generate discrete medical semantic features, and adding a quantization operation during the encoding process;

[0026] Based on the discrete medical semantic features, a binary mask learning module designed based on the minimum description length principle is used to generate a binary mask;

[0027] Using the binary mask to divide the discrete medical semantic features into identity-related discrete medical semantic codes and identity-independent discrete medical semantic codes;

[0028] The identity-independent discrete medical semantic code is reconstructed through the decoder network to obtain the final de-identified medical semantic features, also known as diagnostic semantic information with the minimum description length.

[0029] Optionally, based on the discrete medical semantic features, a binary mask learning module designed based on the minimum description length principle is used to generate a binary mask, including:

[0030] Based on the minimum description length principle, the encoding length of the discrete medical semantic features is minimized to ensure that the information in the feature space is compressed into independent or low-correlation parts;

[0031] A single-layer convolutional network is used to obtain binary masks from discrete medical semantic feature predictions with minimized encoding length.

[0032] Optionally, the method of minimizing the encoding length of the discrete medical semantic features based on the minimum description length principle to ensure that the information in the feature space is compressed into independent or low-correlation parts includes:

[0033]

[0034] Among them, f MFM It is the original feature extracted by the medical basic model. Indicates that the decoder Features reconstructed from the encoded features Q, Represents the feature reconstruction error, represents the accuracy of data fitting, H(Q): the entropy of the encoded feature Q, represents the encoding length of the feature, and β represents the weight for balancing the reconstruction error and encoding length.

[0035] Optionally, the image synthesis method based on a diffusion model is used to fuse the identity information masked image with the diagnostic semantic information of the minimum description length to generate a de-identified image that meets privacy protection requirements and retains clinical information, including:

[0036] The identity information masked image and the de-identified medical semantic features are simultaneously input into the diffusion model;

[0037] In the diffusion model, convolution and back-diffusion operations are used to achieve the transition from a noisy state to a clear state, and the final de-identified medical image is gradually generated.

[0038] A second aspect of the present application provides a medical image privacy protection system with adjustable protection levels, comprising:

[0039] The identity masking module uses a medical identity recognition network to extract local features from the original image and generate an identity similarity heat map. It then binarizes the identity similarity heat map by setting an adjustable threshold to obtain an identity information masked image that meets the privacy protection level.

[0040] The identity-free medical semantic extraction module uses a basic medical model to extract diagnostic semantic information from the original image and adopts a feature separation strategy based on the minimum description length principle to strip away residual identity information and obtain diagnostic semantic information with the minimum description length.

[0041] The image resynthesis module fuses the identity information-shielded image with the diagnostic semantic information of the minimum description length through an image synthesis method based on a diffusion model, thereby generating a de-identified image that meets privacy protection requirements while retaining clinical information.

[0042] According to a third aspect of the present application, a terminal is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor can be used to execute the method described, or to run the system described, when executing the program.

[0043] In a fourth aspect of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the program is executed by a processor, it can be used to execute the method described, or run the system described.

[0044] This application proposes a medical image privacy protection method with adjustable protection levels. This method achieves the technical effect of maximally retaining key diagnostic information in medical images while protecting patient data privacy by decoupling the two major tasks of identity information shielding and medical semantic compensation.

[0045] Other technical effects brought about by the additional features will be further explained in the corresponding embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] Other features, objects and advantages of the present application will become more apparent upon reading the detailed description of non-limiting embodiments with reference to the following drawings:

[0047] Figure 1 This is a flowchart of a medical image privacy protection method with adjustable protection level according to an exemplary embodiment;

[0048] Figure 2 This is a flowchart of a medical image privacy protection method with adjustable protection levels according to an exemplary embodiment;

[0049] Figure 3 The figure is a structural diagram of a medical image privacy protection system with adjustable protection level according to an exemplary embodiment. DETAILED DESCRIPTION

[0050] The present application is described in detail below with reference to specific embodiments. The following examples will help those skilled in the art to further understand the present application, but are not intended to limit the present application in any form. It should be noted that, without departing from the concept of the present application, a number of variations and improvements may be made by those skilled in the art, and these all fall within the scope of protection of the present application. Parts not described in detail in the following examples may be implemented using existing technologies.

[0051] Conventional image processing methods such as blurring, pixelation, or noise injection not only weaken identity features but also severely damage subtle lesion information in the image that is closely related to clinical diagnosis, significantly reducing the practicality of the image in subsequent detection, segmentation, and other tasks. Based on the above issues, the present application provides a medical image privacy protection method with adjustable protection levels to address the above problems.

[0052] Reference Figure 1 and Figure 2 As shown in FIG, a medical image privacy protection method with adjustable protection level is provided, and the steps are as follows:

[0053] S100, using a medical identity recognition network to extract local features from the original image and generate an identity similarity heat map; by setting an adjustable threshold, the identity similarity heat map is binarized to obtain an identity information masked image that meets the privacy protection level.

[0054] Specifically, the "identity information masked image" is obtained by masking some areas; the medical diagnostic semantic information corresponding to these areas will also be lost accordingly.

[0055] S200 uses the medical basic model to extract the diagnostic semantic information from the original image, and adopts the feature separation strategy constructed by the minimum description length principle to strip off the residual identity information and obtain the diagnostic semantic information with the minimum description length.

[0056] Specifically, the diagnostic semantic information of the minimum description length does not include identity information.

[0057] S300, through image synthesis based on a diffusion model, fuses the identity information masked image with diagnostic semantic information of minimum description length to generate a de-identified image that meets privacy protection requirements while retaining clinical information.

[0058] The above embodiment of the present invention decouples the two major tasks of identity information shielding and medical semantic compensation, thereby ensuring the privacy of patient data while retaining the key diagnostic information in the medical images to the greatest extent possible.

[0059] In order to effectively remove the identity information in the original image, in some specific embodiments of the present application, for S100, the following steps S101-S105 can be adopted.

[0060] S101, local feature extraction process: using the pre-trained medical identity recognition network to extract local features of the input original image X to obtain a feature tensor f.

[0061] Specifically, the feature tensor f can be understood as the regionalized digital fingerprint of the current input original image, which can be used to describe the specific features of each region of the image.

[0062] Exemplary: The medical identity recognition network can adopt a medical re-identification (ReID) model, such as a ViT-based network.

[0063] S102, global identity embedding generation: perform spatial average pooling on the feature tensor f extracted above to obtain the global identity embedding vector id.

[0064] S103, similarity graph calculation: calculate the cosine similarity between each local position in the feature tensor f and the global identity embedding vector id to generate a similarity graph S.

[0065] Specifically, the similarity graph S describes the strength of identity specificity of each region. Regions with larger values ​​indicate that they contain more private information and are more likely to be removed.

[0066] S104, identity region binarization: Select an adjustable threshold T to perform binarization processing on the similarity map S to obtain an identity clue binarization map.

[0067] Specifically, the adjustable threshold T can be flexibly set based on privacy requirements (privacy protection level requirements). Generally, privacy requirements are categorized as 5%, 10%, and 20% identity recognition rates. The corresponding adjustable thresholds are set to block out the regions corresponding to the top 95%, 90%, and 80% of the values ​​in the identity clue binary image, respectively. This threshold is defined based on percentiles and is therefore dynamic for each image.

[0068] Binarization means that based on different privacy requirements, larger areas, such as the 95%, 90%, and 80% percentiles mentioned above, are masked (set to 0) and other areas are retained (set to 1).

[0069] S105, Identity Masking Image Generation: The identity clue binarized image is resized to the same spatial resolution as the input image X using nearest neighbor upsampling, and an identity information masking image is obtained through element-wise multiplication. The element-wise multiplication is performed on the identity clue binarized image with the same spatial resolution as the input image X and the input original influence X.

[0070] The above-mentioned embodiments of the present application implement an adjustable privacy protection mechanism. By setting the binarization threshold of the identity similarity map, flexible identity region masking is achieved to meet different privacy requirements, while ensuring that important diagnostic information such as lesions and anatomical structures in the image is preserved.

[0071] In order to obtain medical semantic compensation, in some specific embodiments of the present application, for S200, the following steps S201-S204 can be adopted.

[0072] S201, medical feature extraction: Use a pre-trained medical basic model to extract rich medical features from the original image X to obtain original medical semantic information.

[0073] For example, the medical basic model may be an X-ray feature detector or an eye fundus feature detector, such as the X-ray basic model MGCA or the eye fundus basic model RetFound-ViT.

[0074] S202, Feature Encoding and Discretization: A three-layer convolutional encoder network is used to map the original medical semantic information into a latent discrete code space, generating discrete medical semantic features. Quantization is incorporated into the encoding process to facilitate subsequent entropy estimation and minimum description length calculation of the semantic information.

[0075] Specifically, quantization approximates continuous variables to discrete variables, making entropy estimation for discrete variables relatively easy. The minimum description length is numerically equivalent to the estimated entropy. However, entropy estimation is only useful during training.

[0076] S203, feature separation based on the minimum description length principle: Based on the discrete medical semantic features, a binary mask learning module designed based on the minimum description length principle is used to generate a binary mask M. This mask separates the discrete medical semantic features into identity-related discrete medical semantic codes and identity-independent discrete medical semantic codes.

[0077] Specifically, the minimum description length (MDL) principle is a model selection method in information theory, which aims to find the best description of given data so that the total code length (codelength) of the description is minimized. The core idea of ​​MDL is that a good model should not only be able to fit the data accurately (low reconstruction error), but also be as concise as possible (low model complexity). In information theory, the total description length of the data can be expressed as the sum of the data reconstruction error and the model code length. In this application, the MDL principle is used to construct a compact feature representation space (code space) to separate identity-related information and medical semantic information in medical image features. Specifically, MDL ensures that the information in the feature space is compressed into independent or low-correlation parts by minimizing the code length of the feature (i.e., entropy H(Q)), thereby facilitating the separation of identity and semantic information.

[0078] Mathematically, the goal of the MDL principle can be expressed as optimizing the following rate-distortion loss (Rate-DistortionLoss):

[0079]

[0080] Among them, f MFM It is the original feature extracted by the basic medical model. Indicates that the decoder Features reconstructed from the encoded features Q. represents the feature reconstruction error and indicates the accuracy of data fitting. H(Q): The entropy of the encoded feature Q, which represents the encoding length of the feature. β represents the weight that balances the reconstruction error and encoding length. By minimizing the above losses, MDL ensures that features capture the essential information of the data in a compact representation space while reducing redundancy and correlation, facilitating subsequent identity-semantic separation.

[0081] By minimizing the loss formula, MDL ensures that feature Q captures the essential information of the data in a compact representation space while reducing redundancy and correlation, facilitating subsequent identity-semantic separation.

[0082] Furthermore, in the discrete medical semantic feature space, a binary mask M is learned to separate the features into identity-related and identity-irrelevant parts. The specific steps are as follows:

[0083] S203.1: Feature extraction and discretization. Extract features f from the input medical image X using a pre-trained medical foundation model. MFM Through the encoder ε and quantization operation, f MFM Mapped to a low-dimensional discrete feature space, we get discrete coding: Q = Quantize(ε(f MFM )), where Quantize represents a rounding operation, which quantizes continuous values ​​into integers and generates a 32-channel integer code Q.

[0084] S203.2: Compact Feature Learning with MDL. By minimizing the loss formula above, MDL ensures that feature Q captures the essential information of the data in a compact representation space while reducing redundancy and correlation, facilitating subsequent identity-semantic separation.

[0085] S203.3: Binary Mask Learning. Use a single-layer convolutional network to predict a binary mask M from Q, with the same dimensions as Q. Mask M separates Q into: identity-related encoding: Q id =Q⊙M, and the identity-independent (i.e., semantic part) encoding: Q sem =Q⊙(1-M). By using the minimum description length principle and mask M calculation, identity information and medical semantic information are strictly distinguished in the same latent space.

[0086] S204, semantic feature reconstruction: identity-independent discrete medical semantic code Q sem After reconstruction through the decoder network, the final de-identified medical semantic features are obtained

[0087] To further ensure that no residual identity information is introduced into the image, the above embodiment innovatively introduces a feature separation strategy based on minimum description length. This strategy discretizes continuous feature vectors at the feature encoding end and uses an efficient learning Gaussian mixture model to perform entropy coding estimation on the encoded codebook, so that identity features and medical semantic features are strictly decoupled within the same latent space. By setting different training objectives and constraints for the identity channel and the semantic channel, not only is privacy security guaranteed during the de-identification process, but also high-fidelity recovery of important clinical information in the image is ensured.

[0088] In order to obtain the final image information, in some specific embodiments of the present application, for S300, the following steps S301-S302 can be adopted. Specifically:

[0089] S301, conditional fusion: The identity information masked image obtained by the identity masking module and the de-identified medical semantic features are simultaneously input into the diffusion model. The diffusion model adopts a dual-conditional control mechanism to fully utilize the complementary information of the two in the fusion process. Specifically,

[0090] Specifically, identity masked images It provides low-level spatial structure information of the masked identity area to ensure that the generated image maintains visual consistency with the original image in the non-identity area; and the medical semantic features of the masked identity area are It provides high-level medical semantic information, such as lesion morphology or tissue features, to guide the generation of image restoration and diagnosis-related details. The dual-conditional control mechanism fuses these two complementary information through a bidirectional cross-attention mechanism to generate a unified conditional feature f fuse , to guide the subsequent diffusion process. The specific implementation process is divided into the following steps.

[0091] S301.1: Dimensionality Reduction Projection: Identity-Masked Images Projected to the low-resolution feature space through Down-Net, low-level features f are generated noID Down-Net consists of a variational autoencoder (VAE) encoder with a stable diffusion model and two convolutional layers (kernel size 5, stride 2), and the output feature dimension is:

[0092]

[0093] S301.2: Feature Alignment: De-identified Medical Semantic Features (Usually C is the number of feature channels, h, w is the feature spatial resolution) through convolution operation or upsampling to adjust to f noIDThe same spatial resolution ensures that both have compatible dimensions before fusion.

[0094] S301.3: Bidirectional cross-attention fusion: Adopt bidirectional cross-attention mechanism to fuse f noID and Make full use of the complementary information of the two. The cross-attention mechanism calculates the relevance through query, key and value. The formula is: Among them, Q, K, V are respectively from f noID and Extract, d represents the dimension of the key vector. For example, Q can be extracted from f noID Extract, K, V from Extraction, and vice versa, bidirectional calculation enhances information interaction. After fusion, unified features are generated:

[0095]

[0096] S301.4: Feature Injection: Fusion Feature f fuse The intermediate feature dimensions of the diffusion model UNet are adapted through a series of convolutional layers and serve as conditional input to guide the subsequent reverse diffusion process.

[0097] This dual-conditional control mechanism ensures that the generated image retains both X noID The privacy protection features of medical semantic information, thereby achieving a balance between privacy and practicality.

[0098] S302, Backward Diffusion Synthesis: In the diffusion model, a series of convolution and back diffusion operations are performed to achieve the transition from a noisy state to a clear state, and gradually generate the final de-identified medical image.

[0099] Specifically, the diffusion model is based on the conditional feature f obtained by S301 fusion fuse , from the initial Gaussian noise state z T At the beginning, the noise is gradually removed through the reverse diffusion process to generate a detailed de-identified image Y. This process utilizes the powerful generation ability of the diffusion model and combines the conditional feature f fuse Guided by the principles of CNN, we ensure that the generated images are both visually realistic and meet the requirements of privacy protection and medical semantic preservation. The specific implementation process is divided into the following steps.

[0100] S302.1: Initial Noise State: Backdiffusion starts with random Gaussian noise, representing a completely unstructured latent representation:

[0101] S302.2: Conditional feature guidance: Fusion feature f fuseIt is injected into the UNet of the diffusion model to guide each step of the denoising process. The intermediate features of UNet are combined with f through convolution operation. fuse Combined with:

[0102] UNet(z t ,t)=UNet(z t ,t)+Conv(f fuse ),

[0103] Among them, Conv(f fuse ) Adapt the fusion features to the middle layer dimension of UNet, z t is the potential representation at step t, and t is the number of diffusion steps.

[0104] S302.3: Backward diffusion process: The diffusion model gradually changes from the noise state z through back diffusion. T Generate a clear state z0. The conditional denoising formula for back diffusion is:

[0105]

[0106] Where: μ θ (z t ,t,f fuse ) is the mean value predicted by UNet, subject to the conditional feature f fuse Control. θ (t) is a predefined variance schedule, usually a fixed value. UNet predicts noise ∈ θ (z t ,t,f fuse ), used to calculate the mean: Among them, α t , is the scheduling parameter in the diffusion process.

[0107] S302.4: Image Generation: After T steps of back diffusion, a clear latent representation z0 is obtained. Then, z0 is mapped back to pixel space through the VAE decoder to generate the final de-identified image:

[0108]

[0109] This process starts from a completely random noise state z T At the beginning, based on the fusion condition feature f fuse The image details are gradually restored under the guidance of the noID Privacy features and Medical semantic information.

[0110] In the above-mentioned embodiment of the present application, S301 combines the privacy protection properties of the identity-masked image (masking the identity region) with identity-independent medical semantic information. The backward diffusion process in S302 utilizes a powerful diffusion model (based on the StableDiffusion architecture) to gradually generate visually realistic de-identified images from a noisy state. For example, this allows the generated chest X-ray image to modify identity-related features (such as clavicle shape) while preserving medical manifestations (such as lung shadows).

[0111] Based on the same technical concept, in some specific embodiments of the present application, a medical image privacy protection system 100 with adjustable protection level is provided. Figure 3 Shown, including:

[0112] The identity masking module 110 uses a medical identity recognition network based on a visual transformer to extract local features from the original image and generate an identity similarity heat map. The identity similarity heat map is binarized by setting an adjustable threshold to achieve identity information masking images at different privacy protection levels.

[0113] The identity-free medical semantic extraction module 120 extracts diagnostic semantic information from the original image using a pre-trained medical basic model and uses a feature separation strategy based on the minimum description length principle to strip away residual identity information;

[0114] The image resynthesis module 130 fuses the identity information masked image with the compensated semantic information through an image synthesis method based on a diffusion model to generate a de-identified image that meets privacy protection requirements while retaining clinical information.

[0115] The specific implementation techniques of the modules / units in the above examples of the present invention may refer to the corresponding steps of the medical image privacy protection method with adjustable protection level in the above embodiments, which will not be repeated here.

[0116] The preferred features of the above embodiments can be used alone in any embodiment, or in any combination without conflict. In addition, parts not described in detail in the embodiments can be implemented using existing technologies.

[0117] The following further illustrates the present application in conjunction with specific application examples / comparative examples to facilitate a better understanding of the above technical solutions of the present application. It should be understood that the following are merely partial examples and are not intended to limit the present application.

[0118] The experimental results of the method proposed in the embodiment of this application on public medical imaging datasets include the chest X-ray classification dataset MIMIC-X; the chest X-ray segmentation dataset ChestX-Det; and the fundus photo classification dataset EyePACS.

[0119] The accuracy of the de-identified images shown in Table 1 in the re-identification task is significantly reduced, proving that the method of the embodiment of the present application has the best effect in completely eliminating the original identity information and improving privacy protection performance.

[0120] Table 1 Performance analysis

[0121]

[0122] Optionally, the memory is used to store programs; the memory may include volatile memory (English: volatile memory), such as random-access memory (English: random-access memory, abbreviated: RAM), such as static random-access memory (English: static random-access memory, abbreviated: SRAM), double data rate synchronous dynamic random access memory (English: Double Data Rate Synchronous Dynamic Random Access Memory, abbreviated: DDRSDRAM), etc.; the memory may also include non-volatile memory (English: non-volatile memory), such as flash memory (English: flash memory). The memory is used to store computer programs (such as applications, functional modules, etc. that implement the above-mentioned methods), computer instructions, etc. The above-mentioned computer programs, computer instructions, etc. can be partitioned and stored in one or more memories. And the above-mentioned computer programs, computer instructions, data, etc. can be called by the processor.

[0123] The aforementioned computer programs, computer instructions, etc. may be partitioned and stored in one or more memories, and the aforementioned computer programs, computer instructions, data, etc. may be called by a processor.

[0124] The processor is configured to execute the computer program stored in the memory to implement the various steps of the method involved in the above embodiment. For details, please refer to the relevant description in the above method embodiment.

[0125] The processor and memory can be independent structures or integrated structures. When the processor and memory are independent structures, the memory and processor can be coupled via a bus.

[0126] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0127] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0128] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0129] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0130] The above describes some specific embodiments of the present application. It should be understood that the present application is not limited to the specific embodiments described above, and those skilled in the art may make various variations or modifications within the scope of the claims, which do not affect the substantive content of the present application. The above preferred features may be used in any combination as long as they do not conflict with each other.

Claims

1. A medical image privacy protection method with adjustable protection level, characterized in that: include: Use the medical identity recognition network to extract local features from the original image and generate an identity similarity heat map; Binarizing the identity similarity heat map by setting an adjustable threshold to obtain an identity information masked image that meets the privacy protection level; Extracting diagnostic semantic information from the original image using a medical basic model, and adopting a feature separation strategy based on a minimum description length principle to strip away residual identity information and obtain diagnostic semantic information with a minimum description length; Through an image synthesis method based on a diffusion model, the identity information masked image is fused with diagnostic semantic information of minimum description length to generate a de-identified image that meets privacy protection requirements while retaining clinical information.

2. A medical image privacy protection method with adjustable protection level according to claim 1, characterized in that: The medical identity recognition network is used to extract local features from the original image and generate an identity similarity heat map; Binarizing the identity similarity heat map by setting an adjustable threshold to obtain an identity information masked image that meets the privacy protection level, including: Using a pre-trained medical identity recognition network to extract local features from the original image to obtain a feature tensor; Performing spatial average pooling on the feature tensor to obtain a global identity embedding vector; calculating the cosine similarity between each local position in the feature tensor and the global identity embedding vector to generate a similarity graph; According to the privacy protection level requirement, an adjustable threshold is selected to perform binarization processing on the similarity graph to obtain an identity clue binarization graph; The identity clue binarized image is adjusted to the same spatial resolution as the original image using nearest neighbor upsampling, and an identity information masked image is obtained through an element-by-element multiplication operation.

3. The medical image privacy protection method with adjustable protection level according to claim 2, characterized in that: The method of selecting an adjustable threshold value according to the privacy protection level requirement to perform binarization processing on the similarity graph to obtain an identity clue binarization graph includes: Privacy protection levels include 5% identification rate, 10% identification rate, and 20% identification rate; The corresponding thresholds are 95%, 90%, and 80% areas of the similarity graph, respectively; Select the privacy protection level according to your needs and determine the corresponding threshold; The similarity graph is binarized according to a determined threshold value to obtain an identity clue binarized graph.

4. The medical image privacy protection method with adjustable protection level according to claim 1, characterized in that: The method of extracting the diagnostic semantic information from the original image using the medical basic model and adopting a feature separation strategy based on the minimum description length principle to strip away the residual identity information and obtain the diagnostic semantic information with the minimum description length includes: extracting medical features from the original image using a pre-trained medical basic model to obtain original medical semantic information; Mapping the original medical semantic information into a latent discrete code space using an encoder network based on a three-layer convolution operation to generate discrete medical semantic features, and adding a quantization operation during the encoding process; Based on the discrete medical semantic features, a binary mask learning module designed based on the minimum description length principle is used to generate a binary mask; Using the binary mask to divide the discrete medical semantic features into identity-related discrete medical semantic codes and identity-independent discrete medical semantic codes; The identity-independent discrete medical semantic code is reconstructed through the decoder network to obtain the final de-identified medical semantic features, also known as diagnostic semantic information with the minimum description length.

5. The medical image privacy protection method with adjustable protection level according to claim 4, characterized in that: Based on the discrete medical semantic features, a binary mask learning module designed based on the minimum description length principle is used to generate a binary mask, including: Based on the minimum description length principle, the encoding length of the discrete medical semantic features is minimized to ensure that the information in the feature space is compressed into independent or low-correlation parts; A single-layer convolutional network is used to obtain binary masks from discrete medical semantic feature predictions with minimized encoding length.

6. The medical image privacy protection method with adjustable protection level according to claim 5, characterized in that: The method of minimizing the encoding length of the discrete medical semantic features based on the minimum description length principle to ensure that the information in the feature space is compressed into independent or low-correlation parts includes: Among them, f MFM It is the original feature extracted by the medical basic model. Indicates that the decoder Features reconstructed from the encoded features Q, Represents the feature reconstruction error, represents the accuracy of data fitting, H(Q): the entropy of the encoded feature Q, represents the encoding length of the feature, and β represents the weight for balancing the reconstruction error and encoding length.

7. The medical image privacy protection method with adjustable protection level according to claim 1, characterized in that: The image synthesis method based on the diffusion model is used to fuse the identity information masked image with the diagnostic semantic information of the minimum description length to generate a de-identified image that meets the privacy protection requirements and retains the clinical information, including: The identity information masked image and the de-identified medical semantic features are simultaneously input into the diffusion model; In the diffusion model, convolution and back-diffusion operations are used to achieve the transition from a noisy state to a clear state, and the final de-identified medical image is gradually generated.

8. A medical image privacy protection system with adjustable protection level, characterized in that: include: The identity masking module uses the medical identity recognition network to extract local features from the original image and generate an identity similarity heat map; Binarizing the identity similarity heat map by setting an adjustable threshold to obtain an identity information masked image that meets the privacy protection level; The identity-free medical semantic extraction module uses a basic medical model to extract diagnostic semantic information from the original image and adopts a feature separation strategy based on the minimum description length principle to strip away residual identity information and obtain diagnostic semantic information with the minimum description length. The image resynthesis module fuses the identity information-shielded image with the diagnostic semantic information of the minimum description length through an image synthesis method based on a diffusion model, thereby generating a de-identified image that meets privacy protection requirements while retaining clinical information.

9. A terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, it can be used to perform the method according to any one of claims 1 to 7, or run the system according to claim 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, it can be used to execute the method according to any one of claims 1 to 7, or to run the system according to claim 8.

Citation Information

Patent Citations

  • Medical image processing method, device and equipment based on privacy protection

    CN118315030A