{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,18]],"date-time":"2026-08-18T00:37:43Z","timestamp":1787013463405,"version":"build-2736575974"},"reference-count":68,"publisher":"Springer Science and Business Media LLC","issue":"8126","license":[{"start":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T00:00:00Z","timestamp":1782259200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T00:00:00Z","timestamp":1782259200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Nature"],"published-print":{"date-parts":[[2026,8,6]]},"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Medical artificial intelligence (AI) models hold the promise to improve global access to high-quality diagnostics\n                    <jats:sup>1<\/jats:sup>\n                    . However, the training data underlying these models often contain sensitive patient information that may be exposed through privacy attacks\n                    <jats:sup>2\u20137<\/jats:sup>\n                    . Previous research has primarily quantified the success of these attacks in aggregate, across all records in a dataset. Thus, the privacy risk faced by individual patients, who often contribute multiple similar records to a training dataset, is poorly understood. Here we present one of the first patient-level privacy audits of AI models for medical diagnostic applications. We focus on membership inference attacks\n                    <jats:sup>2\u20134<\/jats:sup>\n                    (MIAs), which seek to determine whether the data of a given individual were used to train a model. Across a diverse range of medical datasets, we show that MIAs can achieve near-perfect success rates for individual patients, even when the aggregate performance does not substantially deviate from random guessing. We further find that the number of patients with high attack success increases substantially with model capacity, and that underrepresented groups\u2014stratified by disease status, self-reported race, insurance, sex or imaging protocol\u2014face disproportionately high attack success. Together, our findings show that aggregate privacy metrics can severely underestimate individual privacy risk. Whether the disparate risk profiles we observe extend to attacks beyond MIAs remains an open question, motivating the further development of risk assessment and mitigation techniques that cater to all data-contributing patients.\n                  <\/jats:p>","DOI":"10.1038\/s41586-026-10688-0","type":"journal-article","created":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:03:30Z","timestamp":1782313410000},"page":"192-198","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Disparate privacy risks from medical AI"],"prefix":"10.1038","volume":"656","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3065-2363","authenticated-orcid":false,"given":"Moritz A.","family":"Knolle","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Martin J.","family":"Menten","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9600-4094","authenticated-orcid":false,"given":"Friederike","family":"Jungmann","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Felix","family":"Meissen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4897-9356","authenticated-orcid":false,"given":"Ben","family":"Glocker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5683-5889","authenticated-orcid":false,"given":"Daniel","family":"Rueckert","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Georgios","family":"Kaissis","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,24]]},"reference":[{"key":"10688_CR1","doi-asserted-by":"publisher","first-page":"1997","DOI":"10.1016\/S0140-6736(21)00673-5","volume":"398","author":"KA Fleming","year":"2021","unstructured":"Fleming, K. A. et al. The Lancet Commission on diagnostics: transforming access to diagnostics. Lancet 398, 1997\u20132050 (2021).","journal-title":"Lancet"},{"key":"10688_CR2","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C. & Shmatikov, V. Membership inference attacks against machine learning models. In Proc. 2017 IEEE Symposium on Security and Privacy (SP) 3\u201318 (IEEE, 2017).","DOI":"10.1109\/SP.2017.41"},{"key":"10688_CR3","doi-asserted-by":"crossref","unstructured":"Carlini, N. et al. Membership inference attacks from first principles. In Proc. 2022 IEEE Symposium on Security and Privacy (SP) 1897\u20131914 (IEEE, 2022).","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"10688_CR4","unstructured":"Zarifzadeh, S., Liu, P. & Shokri, R. Low-cost high-power membership inference attacks. In Proc. 41st International Conference on Machine Learning 58244\u201358282 (PMLR, 2024)."},{"key":"10688_CR5","unstructured":"Carlini, N. et al. Extracting training data from large language models. In Proc. 30th USENIX Security Symposium 2633\u20132650 (USENIX, 2021)."},{"key":"10688_CR6","unstructured":"Carlini, N. et al. Extracting training data from diffusion models. In Proc. 32nd USENIX Security Symposium 5253\u20135270 (USENIX, 2023)."},{"key":"10688_CR7","unstructured":"Nasr, M. et al. Scalable extraction of training data from aligned, production language models. In Proc. Thirteenth International Conference on Learning Representations (ICLR, 2025)."},{"key":"10688_CR8","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M. K. & Ristenpart, T. Stealing machine learning models via prediction APIs. In Proc. 25th USENIX Security Symposium 601\u2013618 (USENIX, 2016)."},{"key":"10688_CR9","unstructured":"Carlini, N. et al. Stealing part of a production language model. In Proc. 41st International Conference on Machine Learning 5680\u20135705 (ICML, 2024)."},{"key":"10688_CR10","doi-asserted-by":"publisher","first-page":"869","DOI":"10.1038\/s41591-024-03398-5","volume":"31","author":"S-K Yoo","year":"2025","unstructured":"Yoo, S.-K. et al. Prediction of checkpoint inhibitor immunotherapy efficacy for cancer using routine blood tests and clinical data. Nat. Med. 31, 869\u2013880 (2025).","journal-title":"Nat. Med."},{"key":"10688_CR11","unstructured":"FDA. Artificial intelligence-enabled medical devices. https:\/\/www.fda.gov\/medical-devices\/software-medical-device-samd\/artificial-intelligence-and-machine-learning-aiml-enabled-medical-devices (2024)."},{"key":"10688_CR12","doi-asserted-by":"publisher","DOI":"10.3390\/healthcare8020133","volume":"8","author":"AH Seh","year":"2020","unstructured":"Seh, A. H. et al. Healthcare data breaches: insights and implications. Healthcare 8, 133 (2020).","journal-title":"Healthcare"},{"key":"10688_CR13","unstructured":"Albert Haro Abad, S. C. Health Threat Landscape: ENISA Report 2023. Technical report (European Union Agency for Cybersecurity, 2023)."},{"key":"10688_CR14","doi-asserted-by":"crossref","unstructured":"Narayanan, A. & Shmatikov, V. Robust de-anonymization of large sparse datasets. In Proc. 2008 IEEE Symposium on Security and Privacy (sp 2008) 111\u2013125 (IEEE, 2008).","DOI":"10.1109\/SP.2008.33"},{"key":"10688_CR15","doi-asserted-by":"publisher","DOI":"10.1126\/sciadv.adn7053","volume":"10","author":"A Gadotti","year":"2024","unstructured":"Gadotti, A., Rocher, L., Houssiau, F., Cre\u0163u, A.-M. & de Montjoye, Y.-A. Anonymization: the imperfect science of using data while preserving privacy. Sci. Adv. 10, eadn7053 (2024).","journal-title":"Sci. Adv."},{"key":"10688_CR16","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-024-55296-6","volume":"16","author":"L Rocher","year":"2025","unstructured":"Rocher, L., Hendrickx, J. M. & de Montjoye, Y.-A. A scaling law to model the effectiveness of identification techniques. Nat. Commun. 16, 347 (2025).","journal-title":"Nat. Commun."},{"key":"10688_CR17","unstructured":"Suri, A., Zhang, X., Evans, D. Do parameters reveal more than loss for membership inference? In Proc. 2nd Workshop on High-dimensional Learning Dynamics (HiLD, 2024)."},{"key":"10688_CR18","unstructured":"Geiping, J., Bauermeister, H., Dr\u00f6ge, H. & Moeller, M. Inverting gradients - how easy is it to break privacy in federated learning? In Proc. 34th International Conference on Neural Information Processing Systems 16937\u201316947 (Curran Associates, 2020)."},{"key":"10688_CR19","unstructured":"Fowl, L. H., Geiping, J., Czaja, W., Goldblum, M. & Goldstein, T. Robbing the fed: directly obtaining private data in federated learning with modified models. In Proc. International Conference on Learning Representations (ICLR, 2022)."},{"key":"10688_CR20","unstructured":"Feng, S. & Tram\u00e8r, F. Privacy backdoors: stealing data with corrupted pretrained models. In Proc. 41st International Conference on Machine Learning 13326\u201313364 (PMLR, 2024)."},{"key":"10688_CR21","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1038\/s41586-021-03583-3","volume":"594","author":"S Warnat-Herresthal","year":"2021","unstructured":"Warnat-Herresthal, S. et al. Swarm Learning for decentralized and confidential clinical machine learning. Nature 594, 265\u2013270 (2021).","journal-title":"Nature"},{"key":"10688_CR22","doi-asserted-by":"publisher","first-page":"861","DOI":"10.1016\/j.patrec.2005.10.010","volume":"27","author":"T Fawcett","year":"2006","unstructured":"Fawcett, T. An introduction to ROC analysis. Pattern Recognit. Lett. 27, 861\u2013874 (2006).","journal-title":"Pattern Recognit. Lett."},{"key":"10688_CR23","doi-asserted-by":"publisher","first-page":"29","DOI":"10.1148\/radiology.143.1.7063747","volume":"143","author":"JA Hanley","year":"1982","unstructured":"Hanley, J. A. & McNeil, B. J. The meaning and use of the area under a receiver operating characteristic (ROC) curve. Radiology 143, 29\u201336 (1982).","journal-title":"Radiology"},{"key":"10688_CR24","unstructured":"Cohen, J. P. et al. TorchXRayVision: a library of chest X-ray datasets and models. In Proc. 5th International Conference on Medical Imaging with Deep Learning 231\u2013249 (PMLR, 2022)."},{"key":"10688_CR25","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2020.101797","volume":"66","author":"A Bustos","year":"2020","unstructured":"Bustos, A., Pertusa, A., Salinas, J.-M. & de la Iglesia-Vay\u00e1, M. PadChest: a large chest x-ray image dataset with multi-label annotated reports. Med. Image Anal. 66, 101797 (2020).","journal-title":"Med. Image Anal."},{"key":"10688_CR26","doi-asserted-by":"crossref","unstructured":"Irvin, J. et al. CheXpert: a large chest radiograph dataset with uncertainty labels and expert comparison. In Proc. Thirty-Third AAAI Conference on Artificial Intelligence 590\u2013597 (PKP Publishing, 2019).","DOI":"10.1609\/aaai.v33i01.3301590"},{"key":"10688_CR27","doi-asserted-by":"publisher","DOI":"10.1038\/s41597-019-0322-0","volume":"6","author":"AEW Johnson","year":"2019","unstructured":"Johnson, A. E. W. et al. MIMIC-CXR, a de-identified publicly available database of chest radiographs with free-text reports. Sci. Data 6, 317 (2019).","journal-title":"Sci. Data"},{"key":"10688_CR28","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M. & Jha, S. Privacy risk in machine learning: analyzing the connection to overfitting. In Proc. 2018 IEEE 31st Computer Security Foundations Symposium (CSF) 268\u2013282 (IEEE, 2018).","DOI":"10.1109\/CSF.2018.00027"},{"key":"10688_CR29","unstructured":"Johnson, A. et al. MIMIC-IV-ED (v.1.0) (PhysioNet, 2021)."},{"key":"10688_CR30","doi-asserted-by":"publisher","DOI":"10.1038\/s41597-020-0495-6","volume":"7","author":"P Wagner","year":"2020","unstructured":"Wagner, P. et al. PTB-XL, a large publicly available electrocardiography dataset. Sci. Data 7, 154 (2020).","journal-title":"Sci. Data"},{"key":"10688_CR31","doi-asserted-by":"publisher","unstructured":"Kaplan, J. et al. Scaling laws for neural language models. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2001.08361 (2020).","DOI":"10.48550\/arXiv.2001.08361"},{"key":"10688_CR32","doi-asserted-by":"crossref","unstructured":"Groh, M. et al. Evaluating deep neural networks trained on clinical images in dermatology with the fitzpatrick 17k dataset. In Proc. 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW) 1820\u20131828 (CVPRW, 2021).","DOI":"10.1109\/CVPRW53098.2021.00201"},{"key":"10688_CR33","doi-asserted-by":"crossref","unstructured":"Zagoruyko, S. & Komodakis, N. Wide residual networks. In Proc. British Machine Vision Conference (BMVC) (eds Wilson, R. C. et al.) 87.1\u201387.12 (BMVA Press, 2016).","DOI":"10.5244\/C.30.87"},{"key":"10688_CR34","unstructured":"Dosovitskiy, A. et al. An image is worth 16x16 words: transformers for image recognition at scale. In Proc. IEEE\/CVF Conference on Computer Vision and Pattern Recognition 45\u201367 (ICLR, 2021)."},{"key":"10688_CR35","unstructured":"Raghu, M., Zhang, C., Kleinberg, J. & Bengio, S. Transfusion: understanding transfer learning for medical imaging. In Proc. 33rd International Conference on Neural Information Processing Systems 3347\u20133357 (NIPS, 2019)."},{"key":"10688_CR36","doi-asserted-by":"publisher","first-page":"2176","DOI":"10.1038\/s41591-021-01595-0","volume":"27","author":"L Seyyed-Kalantari","year":"2021","unstructured":"Seyyed-Kalantari, L., Zhang, H., McDermott, M. B. A., Chen, I. Y. & Ghassemi, M. Underdiagnosis bias of artificial intelligence algorithms applied to chest radiographs in under-served patient populations. Nat. Med. 27, 2176\u20132182 (2021).","journal-title":"Nat. Med."},{"key":"10688_CR37","doi-asserted-by":"publisher","DOI":"10.1126\/sciadv.abq6147","volume":"8","author":"R Daneshjou","year":"2022","unstructured":"Daneshjou, R. et al. Disparities in dermatology AI performance on a diverse, curated clinical image set. Sci. Adv. 8, eabq6147 (2022).","journal-title":"Sci. Adv."},{"key":"10688_CR38","doi-asserted-by":"publisher","DOI":"10.1148\/ryai.220047","volume":"5","author":"JJ Jeong","year":"2023","unstructured":"Jeong, J. J. et al. The EMory BrEast imaging Dataset (EMBED): a racially diverse, granular dataset of 3.4 million screening and diagnostic mammographic images. Radiol. Artif. Intell. 5, e220047 (2023).","journal-title":"Radiol. Artif. Intell."},{"key":"10688_CR39","doi-asserted-by":"crossref","unstructured":"Long, Y. et al. A pragmatic approach to membership inferences on machine learning models. In Proc. 2020 IEEE European Symposium on Security and Privacy (EuroS&P) 521\u2013534 (IEEE, 2020).","DOI":"10.1109\/EuroSP48549.2020.00040"},{"key":"10688_CR40","doi-asserted-by":"crossref","unstructured":"Aerni, M., Zhang, J. & Tram\u00e8r, F. Evaluations of machine learning privacy defenses are misleading. In Proc. 2024 on ACM SIGSAC Conference on Computer and Communications Security 1271\u20131284 (CCS, 2024).","DOI":"10.1145\/3658644.3690194"},{"key":"10688_CR41","doi-asserted-by":"crossref","unstructured":"Kulynych, B., Yaghini, M. & Cherubin, G., Veale, M., Troncoso, C. Disparate vulnerability to membership inference attacks. In Proc. Privacy Enhancing Technologies 460\u2013480 (sciendo, 2022).","DOI":"10.2478\/popets-2022-0023"},{"key":"10688_CR42","doi-asserted-by":"crossref","unstructured":"Chang, H. & Shokri, R. On the privacy risks of algorithmic fairness. In Proc. 2021 IEEE European Symposium on Security and Privacy (EuroS&P) 292\u2013303 (IEEE, 2021).","DOI":"10.1109\/EuroSP51992.2021.00028"},{"key":"10688_CR43","unstructured":"Carlini, N. et al. Quantifying memorization across neural language models. In Proc. Eleventh International Conference on Learning Representations (ICLR, 2023)."},{"key":"10688_CR44","doi-asserted-by":"crossref","unstructured":"Feldman, V. Does learning require memorization? a short tale about a long tail. In Proc. 52nd Annual ACM SIGACT Symposium on Theory of Computing 954\u2013959 (STOC, 2020).","DOI":"10.1145\/3357713.3384290"},{"key":"10688_CR45","unstructured":"Feldman, V. & Zhang, C. What neural networks memorize and why: discovering the long tail via influence estimation. In Proc. 34th International Conference on Neural Information Processing Systems 2881\u20132891 (NIPS, 2020)."},{"key":"10688_CR46","unstructured":"World Health Organization et al. World Report on Social Determinants of Health Equity, 2025 (WHO, 2025)."},{"key":"10688_CR47","doi-asserted-by":"publisher","first-page":"447","DOI":"10.1126\/science.aax2342","volume":"366","author":"Z Obermeyer","year":"2019","unstructured":"Obermeyer, Z., Powers, B., Vogeli, C. & Mullainathan, S. Dissecting racial bias in an algorithm used to manage the health of populations. Science 366, 447\u2013453 (2019).","journal-title":"Science"},{"key":"10688_CR48","doi-asserted-by":"publisher","first-page":"211","DOI":"10.1561\/0400000042","volume":"9","author":"C Dwork","year":"2014","unstructured":"Dwork, C. & Roth, A. The algorithmic foundations of differential privacy. Foundations Trends Theoret. Comput. Sci. 9, 211\u2013487 (2014).","journal-title":"Foundations Trends Theoret. Comput. Sci."},{"key":"10688_CR49","doi-asserted-by":"crossref","unstructured":"Abadi, M. et al. Deep learning with differential privacy. In Proc. 2016 ACM SIGSAC Conference on Computer and Communications Security 308\u2013318 (CCS, 2016).","DOI":"10.1145\/2976749.2978318"},{"key":"10688_CR50","doi-asserted-by":"crossref","unstructured":"Nasr, M., Songi, S., Thakurta, A., Papernot, N. & Carlini, N. Adversary instantiation: lower bounds for differentially private machine learning. In Proc. 2021 IEEE Symposium on Security and Privacy (SP) 866\u2013882 (IEEE, 2021).","DOI":"10.1109\/SP40001.2021.00069"},{"key":"10688_CR51","doi-asserted-by":"publisher","first-page":"764","DOI":"10.1038\/s42256-024-00858-y","volume":"6","author":"A Ziller","year":"2024","unstructured":"Ziller, A. et al. Reconciling privacy and accuracy in AI for medical imaging. Nat. Mach. Intell. 6, 764\u2013774 (2024).","journal-title":"Nat. Mach. Intell."},{"key":"10688_CR52","doi-asserted-by":"publisher","unstructured":"Berrada, L. et al. Unlocking accuracy and fairness in differentially private image classification. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2308.10888 (2023).","DOI":"10.48550\/arXiv.2308.10888"},{"key":"10688_CR53","doi-asserted-by":"publisher","unstructured":"De, S., Berrada, L., Hayes, J., Smith, S. L. & Balle, B. Unlocking high-accuracy differentially private image classification through scale. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2204.13650 (2022).","DOI":"10.48550\/arXiv.2204.13650"},{"key":"10688_CR54","unstructured":"Mckenna, R. et al. Scaling laws for differentially private language models. In Proc. 42nd International Conference on Machine Learning 43375\u201343398 (PMLR, 2025)."},{"key":"10688_CR55","doi-asserted-by":"publisher","unstructured":"Johnson, A. E. W. et al. MIMIC-CXR-JPG, a large publicly available database of labeled chest radiographs. Preprint at https:\/\/doi.org\/10.48550\/arXiv.1901.07042 (2019).","DOI":"10.48550\/arXiv.1901.07042"},{"key":"10688_CR56","doi-asserted-by":"publisher","unstructured":"Luo, Y. et al. FairVision: equitable deep learning for eye disease screening via fair identity scaling. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2310.02492 (2023).","DOI":"10.48550\/arXiv.2310.02492"},{"key":"10688_CR57","doi-asserted-by":"publisher","DOI":"10.1038\/s43856-024-00446-6","volume":"4","author":"G Khara","year":"2024","unstructured":"Khara, G. et al. Generalisable deep learning method for mammographic density prediction across imaging techniques and self-reported race. Commun. Med. 4, 21 (2024).","journal-title":"Commun. Med."},{"key":"10688_CR58","doi-asserted-by":"crossref","unstructured":"Wang, Z., Yan, W. & Oates, T. Time series classification from scratch with deep neural networks: a strong baseline. In Proc. 2017 International Joint Conference on Neural Networks (IJCNN) 1578\u20131585 (IEEE, 2017).","DOI":"10.1109\/IJCNN.2017.7966039"},{"key":"10688_CR59","doi-asserted-by":"publisher","DOI":"10.1038\/s41597-022-01782-9","volume":"9","author":"F Xie","year":"2022","unstructured":"Xie, F. et al. Benchmarking emergency department prediction models with machine learning and public electronic health records. Sci. Data 9, 658 (2022).","journal-title":"Sci. Data"},{"key":"10688_CR60","unstructured":"Gorishniy, Y., Rubachev, I., Khrulkov, V. & Babenko, A. Revisiting deep learning models for tabular data. In Proc. 35th International Conference on Neural Information Processing Systems (eds Ranzato, M. et al.) 18932\u201318943 (NIPS, 2021)."},{"key":"10688_CR61","unstructured":"Chollet, F. et al. Keras. https:\/\/keras.io (2015)."},{"key":"10688_CR62","unstructured":"Bradbury, J. et al. JAX: composable transformations of Python+NumPy programs. GitHub http:\/\/github.com\/google\/jax (2026)."},{"key":"10688_CR63","unstructured":"Kingma, D. P. & Ba, J. Adam: a method for stochastic optimization. In Proc. 3rd International Conference on Learning Representations (ICLR, 2015)."},{"key":"10688_CR64","unstructured":"Balle, B. et al. JAX-Privacy: algorithms for privacy-preserving machine learning in JAX. GitHub http:\/\/github.com\/google-deepmind\/jax_privacy (2026)."},{"key":"10688_CR65","doi-asserted-by":"publisher","first-page":"1113","DOI":"10.1613\/jair.1.14649","volume":"77","author":"N Ponomareva","year":"2023","unstructured":"Ponomareva, N. et al. How to DP-fy ML: a practical guide to machine learning with differential privacy. J. Artif. Intell. Res. 77, 1113\u20131201 (2023).","journal-title":"J. Artif. Intell. Res."},{"key":"10688_CR66","doi-asserted-by":"publisher","unstructured":"Balle, B., Barthe, G. & Gaboardi, M. Privacy profiles and amplification by subsampling. J. Priv. Confid. https:\/\/doi.org\/10.29012\/jpc.726 (2020).","DOI":"10.29012\/jpc.726"},{"key":"10688_CR67","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1111\/rssb.12454","volume":"84","author":"J Dong","year":"2022","unstructured":"Dong, J., Roth, A. & Su, W. J. Gaussian differential privacy. J. R. Stat. Soc. Ser. B. 84, 3\u201337 (2022).","journal-title":"J. R. Stat. Soc. Ser. B."},{"key":"10688_CR68","doi-asserted-by":"publisher","unstructured":"moritzknolle. moritzknolle\/leakoscope: V1 (v.v1). Zenodo https:\/\/doi.org\/10.5281\/zenodo.20124226 (2026).","DOI":"10.5281\/zenodo.20124226"}],"container-title":["Nature"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.nature.com\/articles\/s41586-026-10688-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.nature.com\/articles\/s41586-026-10688-0","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/www.nature.com\/articles\/s41586-026-10688-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,6]],"date-time":"2026-08-06T05:33:11Z","timestamp":1785994391000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.nature.com\/articles\/s41586-026-10688-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,24]]},"references-count":68,"journal-issue":{"issue":"8126","published-print":{"date-parts":[[2026,8,6]]}},"alternative-id":["10688"],"URL":"https:\/\/doi.org\/10.1038\/s41586-026-10688-0","relation":{},"ISSN":["0028-0836","1476-4687"],"issn-type":[{"value":"0028-0836","type":"print"},{"value":"1476-4687","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,24]]},"assertion":[{"value":"18 March 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 May 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"24 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 July 2026","order":5,"name":"change_date","label":"Change Date","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Update","order":6,"name":"change_type","label":"Change Type","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"In the version of this aritcle initially published, Ben Glocker (Department of Computing, Imperial College London, London, UK) was listed with an incorrect affiliation; the affiliation is now amended in the HTML and PDF versions of the article.","order":7,"name":"change_details","label":"Change Details","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"B.G. is a part-time employee at DeepHealth. G.K. is a part-time employee at Google DeepMind.","order":1,"name":"Ethics","label":"Competing interests","group":{"name":"EthicsHeading","label":"Ethics"}}]}}