Hybrid Differentially Private Conditional Diffusion for Synthetic EHR Generation in Medical IoT Environments
DOI:
https://doi.org/10.66279/yg5rr373Keywords:
Differential Privacy, Conditional Diffusion, Electronic Health Record, Medical IoT, MIMIC IIIAbstract
Privacy-preserving synthesis of electronic health records is difficult because clinical data combine continuous measurements, categorical diagnoses, class imbalance, missingness, and multiple trust boundaries. PrivMedSynth is presented as a conditional diffusion framework for mixed type tabular health records in Medical Internet of Things edge cloud environments. The framework applies a local randomizer before transmission and trains a conditional diffusion model with differentially private stochastic gradient descent in the cloud. Continuous features are perturbed with a calibrated Gaussian mechanism, categorical variables are protected with generalized randomized response, and clinical conditions are used as explicit generation controls. Rényi differential privacy accounts for repeated cloud updates and is converted to an approximate differential privacy guarantee. The revised formulation distinguishes the formal privacy guarantee from empirical membership inference performance and makes the privacy unit, adjacency relation, modality budget, and noise parameterization explicit. The experiments report a total variation distance of 0.041, a downstream AUROC of 0.884, and a membership inference AUROC of 0.503 on MIMIC III. These utility and attack results remain conditional on the stated preprocessing and require reproduction under the corrected accounting before being interpreted as a final end to end guarantee. The framework provides a principled basis for studying the privacy and utility tradeoff in distributed synthetic clinical data generation.
Downloads
References
[1] A. E. Johnson, T. J. Pollard, L. Shen, L.-w. H. Lehman, M. Feng, M. Ghassemi, B. Moody, P. Szolovits, L. Anthony Celi, and R. G. Mark, “Mimic-iii, a freely accessible critical care database,” Scientific data, vol. 3, no. 1, p. 160035, 2016. DOI: https://doi.org/10.1038/sdata.2016.35
[2] C. Dwork, F. McSherry, K. Nissim, and A. Smith, “Calibrating noise to sensitivity in private data analysis,” in Theory of cryptography conference, pp. 265–284, Springer, 2006. DOI: https://doi.org/10.1007/11681878_14
[3] A. Kotelnikov, D. Baranchuk, I. Rubachev, and A. Babenko, “Tabddpm: Modelling tabular data with diffusion models,” in International conference on machine learning, pp. 17564–17579, PMLR, 2023.
[4] M. L. Fang, D. S. Dhami, and K. Kersting, “Dp-ctgan: Differentially private medical data generation using ctgans,” in International conference on artificial intelligence in medicine, pp. 178–188, Springer, 2022. DOI: https://doi.org/10.1007/978-3-031-09342-5_17
[5] C. Zhu, J. Tang, J. F. Pérez, M. van Dijk, and L. Y. Chen, “Dp-tldm: Differentially private tabular latent diffusion model,” in International Conference on Availability, Reliability and Security, pp. 337–357, Springer, 2025. DOI: https://doi.org/10.1007/978-3-032-00624-0_17
[6] S. L. Warner, “Randomized response: A survey technique for eliminating evasive answer bias,” Journal of the American statistical association, vol. 60, no. 309, pp. 63–69, 1965. DOI: https://doi.org/10.1080/01621459.1965.10480775
[7] Z. Li, B. Wang, J. Li, Y. Hua, and S. Zhang, “Local differential privacy protection for wearable device data,” Plos one, vol. 17, no. 8, p. e0272766, 2022. DOI: https://doi.org/10.1371/journal.pone.0272766
[8] M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp. 308–318, 2016. DOI: https://doi.org/10.1145/2976749.2978318
[9] I. Mironov, “Rényi differential privacy,” in 2017 IEEE 30th computer security foundations symposium (CSF), pp. 263–275, IEEE, 2017. DOI: https://doi.org/10.1109/CSF.2017.11
[10] Z. Zhang, C. Yan, and B. A. Malin, “Membership inference attacks against synthetic health data,” Journal of biomedical informatics, vol. 125, p. 103977, 2022. DOI: https://doi.org/10.1016/j.jbi.2021.103977
[11] C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Foundations and trends® in theoretical computer science, vol. 9, no. 3-4, pp. 211–487, 2014. DOI: https://doi.org/10.1561/0400000042
[12] J. Ho, A. Jain, and P. Abbeel, “Denoising diffusion probabilistic models,” Advances in neural information processing systems, vol. 33, pp. 6840–6851, 2020.
[13] T. J. Pollard, A. E. Johnson, J. D. Raffa, L. A. Celi, R. G. Mark, and O. Badawi, “The eicu collaborative research database, a freely available multi-center database for critical care research,” Scientific data, vol. 5, no. 1, p. 180178, 2018. DOI: https://doi.org/10.1038/sdata.2018.178
[14] I. Silva and G. Moody, “An open-source toolbox for analysing and processing physionet databases in matlab and octave,” Journal of open research software, vol. 2, no. 1, 2014. DOI: https://doi.org/10.5334/jors.bi
Downloads
Published
Data Availability Statement
DATA AVAILABILITY
The datasets analyzed during this study are publicly available from the PhysioNet repository and the UCI Machine Learning
Repository. The MIMIC-III and eICU datasets are available through PhysioNet subject to registration, credentialing, and
applicable data-use requirements. The PhysioNet CinC-2012 dataset is publicly available through PhysioNet, and the UCI
Heart Disease dataset is available from the UCI Machine Learning Repository.
Issue
Section
Categories
License
Copyright (c) 2026 Journal of Smart Algorithms and Applications (JSAA)

This work is licensed under a Creative Commons Attribution 4.0 International License.
Journal of Smart Algorithms and Applications (JSAA) content is published under a Creative Commons Attribution 4.0 International (CC BY 4.0) License. This means that content is freely available to all readers upon publication, and content is published as soon as production is complete.
Journal of Smart Algorithms and Applications (JSAA) seeks to publish the most influential papers that will significantly advance scientific understanding. Selected articles must present new and widely significant data, syntheses, or concepts. They should merit recognition by the wider scientific community and the general public through publication in a reputable scientific journal.



