{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,7,11]],"date-time":"2025-07-11T10:47:17Z","timestamp":1752230837817,"version":"3.27.0"},"reference-count":0,"publisher":"IOS Press","isbn-type":[{"value":"9781643685489","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,10,16]],"date-time":"2024-10-16T00:00:00Z","timestamp":1729036800000},"content-version":"unspecified","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,10,16]]},"abstract":"<jats:p>Many AI applications now attempt to infer users\u2019 mental health conditions, such as depression, from their speech data. In addition to the spoken words, the speech audio contains information about speaker\u2019s identity and demographic attributes, exposing users to serious privacy risks. Previous efforts have primarily focused on developing deep models that preserve privacy; however, there have been few attempts to systematically assess and quantify privacy risks in such systems. We present the first framework for systematically assessing privacy risks in a multimodal (audio-lexical) depression detection system particularly looking at attribute inference attacks. Unlike past works that considered only white-box gender inference attacks against unimodal systems, our framework designs novel white-box and black-box attacks across multiple modalities against three protected speaker attributes: gender, age and education level. We present extensive results on a large, clinically validated dataset, demonstrating critical vulnerability of depression detection systems, where an adversary can infer speaker attributes with 59% - 68% accuracy even for inputs as short as 10 seconds of speech. Our results offer insights and guidelines to inform the development and benchmarking of privacy-preserving models for speech-based depression detection systems. Our code and data are available at: https:\/\/github.com\/apr-aia\/privacy_risks<\/jats:p>","DOI":"10.3233\/faia240941","type":"book-chapter","created":{"date-parts":[[2024,10,17]],"date-time":"2024-10-17T13:45:20Z","timestamp":1729172720000},"source":"Crossref","is-referenced-by-count":2,"title":["Assessing Privacy Risks of Attribute Inference Attacks Against Speech-Based Depression Detection System"],"prefix":"10.3233","author":[{"given":"Basmah","family":"Alsenani","sequence":"first","affiliation":[{"name":"University of Glasgow, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anna","family":"Esposito","sequence":"additional","affiliation":[{"name":"Universit\u00e0 della Campania, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessandro","family":"Vinciarelli","sequence":"additional","affiliation":[{"name":"University of Glasgow, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tanaya","family":"Guha","sequence":"additional","affiliation":[{"name":"University of Glasgow, UK"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"7437","container-title":["Frontiers in Artificial Intelligence and Applications","ECAI 2024"],"original-title":[],"link":[{"URL":"https:\/\/ebooks.iospress.nl\/pdf\/doi\/10.3233\/FAIA240941","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,17]],"date-time":"2024-10-17T13:45:20Z","timestamp":1729172720000},"score":1,"resource":{"primary":{"URL":"https:\/\/ebooks.iospress.nl\/doi\/10.3233\/FAIA240941"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,16]]},"ISBN":["9781643685489"],"references-count":0,"URL":"https:\/\/doi.org\/10.3233\/faia240941","relation":{},"ISSN":["0922-6389","1879-8314"],"issn-type":[{"value":"0922-6389","type":"print"},{"value":"1879-8314","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,16]]}}}