{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T21:22:48Z","timestamp":1780435368284,"version":"3.54.1"},"reference-count":43,"publisher":"Frontiers Media SA","license":[{"start":{"date-parts":[[2023,7,5]],"date-time":"2023-07-05T00:00:00Z","timestamp":1688515200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["frontiersin.org"],"crossmark-restriction":true},"short-container-title":["Front. Bioinform."],"abstract":"<jats:p>Artificial Intelligence (AI) has achieved remarkable success in image generation, image analysis, and language modeling, making data-driven techniques increasingly relevant in practical real-world applications, promising enhanced creativity and efficiency for human users. However, the deployment of AI in high-stakes domains such as infrastructure and healthcare still raises concerns regarding algorithm accountability and safety. The emerging field of explainable AI (XAI) has made significant strides in developing interfaces that enable humans to comprehend the decisions made by data-driven models. Among these approaches, concept-based explainability stands out due to its ability to align explanations with high-level concepts familiar to users. Nonetheless, early research in adversarial machine learning has unveiled that exposing model explanations can render victim models more susceptible to attacks. This is the first study to investigate and compare the impact of concept-based explanations on the privacy of Deep Learning based AI models in the context of biomedical image analysis. An extensive privacy benchmark is conducted on three different state-of-the-art model architectures (ResNet50, NFNet, ConvNeXt) trained on two biomedical (ISIC and EyePACS) and one synthetic dataset (SCDB). The success of membership inference attacks while exposing varying degrees of attribution-based and concept-based explanations is systematically compared. The findings indicate that, in theory, concept-based explanations can potentially increase the vulnerability of a private AI system by up to 16% compared to attributions in the baseline setting. However, it is demonstrated that, in more realistic attack scenarios, the threat posed by explanations is negligible in practice. Furthermore, actionable recommendations are provided to ensure the safe deployment of concept-based XAI systems. In addition, the impact of differential privacy (DP) on the quality of concept-based explanations is explored, revealing that while negatively influencing the explanation ability, DP can have an adverse effect on the models\u2019 privacy.<\/jats:p>","DOI":"10.3389\/fbinf.2023.1194993","type":"journal-article","created":{"date-parts":[[2023,7,5]],"date-time":"2023-07-05T22:47:56Z","timestamp":1688597276000},"update-policy":"https:\/\/doi.org\/10.3389\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Translating theory into practice: assessing the privacy implications of concept-based explanations for biomedical AI"],"prefix":"10.3389","volume":"3","author":[{"given":"Adriano","family":"Lucieri","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andreas","family":"Dengel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sheraz","family":"Ahmed","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1965","published-online":{"date-parts":[[2023,7,5]]},"reference":[{"key":"B1","first-page":"308","article-title":"Deep learning with differential privacy","author":"Abadi","year":"2016"},{"key":"B2","unstructured":"Model extraction from counterfactual explanations\n            A\u00efvodjiU.\n            BolotA.\n            GambsS.\n          2020"},{"key":"B3","doi-asserted-by":"publisher","first-page":"125","DOI":"10.3390\/technologies10060125","article-title":"Privacy and explainability: The effects of data protection on shapley values","volume":"10","author":"Bozorgpanah","year":"2022","journal-title":"Technologies"},{"key":"B4","doi-asserted-by":"publisher","first-page":"102305","DOI":"10.1016\/j.media.2021.102305","article-title":"Analysis of the isic image datasets: Usage, benchmarks and recommendations","volume":"75","author":"Cassidy","year":"2022","journal-title":"Med. Image Anal."},{"key":"B5","unstructured":"Dermatologist-like explainable ai enhances trust and confidence in diagnosing melanoma\n            ChandaT.\n            HauserK.\n            HobelsbergerS.\n            BucherT.-C.\n            GarciaC. N.\n            WiesC.\n          2023"},{"key":"B6","first-page":"839","article-title":"Grad-cam++: Generalized gradient-based visual explanations for deep convolutional networks","author":"Chattopadhay","year":"2018"},{"key":"B7","first-page":"1964","article-title":"Label-only membership inference attacks","author":"Choquette-Choo","year":"2021"},{"key":"B8","article-title":"Laying down harmonised rules on artificial intelligence (artificial intelligence act) and amending certain union legislative acts","author":"Commission","year":"2021"},{"key":"B9","unstructured":"Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95\/46\/EC (General Data Protection Regulation)\n            Council of the European Union\n          2016"},{"key":"B10","first-page":"416","article-title":"Inferring sensitive attributes from model explanations","author":"Duddu","year":"2022"},{"key":"B11","first-page":"15","article-title":"Neither private nor fair: Impact of data imbalance on utility and fairness in differential privacy","author":"Farrand","year":"2020"},{"key":"B12","first-page":"2950","article-title":"Understanding deep networks via extremal perturbations and smooth masks","author":"Fong","year":"2019"},{"key":"B13","doi-asserted-by":"publisher","first-page":"1047","DOI":"10.3390\/e23081047","article-title":"Toward learning trustworthily from data combining privacy, fairness, and explainability: An application to face recognition","volume":"23","author":"Franco","year":"2021","journal-title":"Entropy"},{"key":"B14","first-page":"e1495","article-title":"Deepfixcx: Explainable privacy-preserving image compression for medical image analysis","volume-title":"Wiley interdisciplinary reviews: Data mining and knowledge discovery","author":"Gaudio","year":"2023"},{"key":"B15","doi-asserted-by":"publisher","first-page":"1350","DOI":"10.17863\/CAM.58412","article-title":"Show us the data: Privacy, explainability, and why the law can\u2019t have both","volume":"88","author":"Grant","year":"2020","journal-title":"Geo. Wash. L. Rev."},{"key":"B17","doi-asserted-by":"publisher","first-page":"538","DOI":"10.1109\/jbhi.2018.2824327","article-title":"Seven-point checklist and skin lesion classification using multitask multimodal neural nets","volume":"23","author":"Kawahara","year":"2018","journal-title":"IEEE J. Biomed. health Inf."},{"key":"B18","first-page":"2668","article-title":"Interpretability beyond feature attribution: Quantitative testing with concept activation vectors (tcav)","author":"Kim","year":"2018"},{"key":"B19","first-page":"880","article-title":"Membership leakage in label-only exposures","author":"Li","year":"2021"},{"key":"B20","doi-asserted-by":"publisher","first-page":"106620","DOI":"10.1016\/j.cmpb.2022.106620","article-title":"Exaid: A multimodal explanation framework for computer-aided diagnosis of skin lesions","volume":"215","author":"Lucieri","year":"2022","journal-title":"Comput. Methods Programs Biomed."},{"key":"B21","first-page":"1","article-title":"On interpretability of deep learning based skin lesion classifiers using concept activation vectors","author":"Lucieri","year":""},{"key":"B22","first-page":"185","article-title":"Explaining ai-based decision support systems using concept localization maps","author":"Lucieri","year":""},{"key":"B23","first-page":"1","article-title":"Model reconstruction from model explanations","author":"Milli","year":"2019"},{"key":"B24","unstructured":"Towards privacy-preserving explanations in medical image analysis\n            MontenegroH.\n            SilvaW.\n            CardosoJ. S."},{"key":"B25","doi-asserted-by":"publisher","first-page":"148037","DOI":"10.1109\/access.2021.3124844","article-title":"Privacy-preserving generative adversarial network for case-based explainability in medical image analysis","volume":"9","author":"Montenegro","year":"","journal-title":"IEEE Access"},{"key":"B26","doi-asserted-by":"publisher","first-page":"28333","DOI":"10.1109\/access.2022.3157589","article-title":"Privacy-preserving case-based explanations: Enabling visual interpretability by protecting privacy","volume":"10","author":"Montenegro","year":"2022","journal-title":"IEEE Access"},{"key":"B27","first-page":"3766","article-title":"Xai handbook: Towards a unified framework for explainable ai","author":"Palacio","year":"2021"},{"key":"B28","unstructured":"Rise: Randomized input sampling for explanation of black-box models\n            PetsiukV.\n            DasA.\n            SaenkoK.\n          2018"},{"key":"B29","first-page":"1135","article-title":"\u201cWhy should i trust you?\u201d explaining the predictions of any classifier","author":"Ribeiro","year":"2016"},{"key":"B30","unstructured":"Privacy meets explainability: A comprehensive impact benchmark\n            SaifullahS.\n            MercierD.\n            LucieriA.\n            DengelA.\n            AhmedS.\n          2022"},{"key":"B31","article-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models","author":"Salem","year":"2018"},{"key":"B32","first-page":"618","article-title":"Grad-cam: Visual explanations from deep networks via gradient-based localization","author":"Selvaraju","year":"2017"},{"key":"B33","first-page":"231","article-title":"On the privacy risks of model explanations","author":"Shokri","year":"2021"},{"key":"B34","first-page":"3","article-title":"Membership inference attacks against machine learning models","author":"Shokri","year":"2017"},{"key":"B35","first-page":"3145","article-title":"Learning important features through propagating activation differences","author":"Shrikumar","year":"2017"},{"key":"B36","unstructured":"Deep inside convolutional networks: Visualising image classification models and saliency maps\n            SimonyanK.\n            VedaldiA.\n            ZissermanA.\n          2013"},{"key":"B37","first-page":"3319","article-title":"Axiomatic attribution for deep networks","author":"Sundararajan","year":"2017"},{"key":"B38","doi-asserted-by":"publisher","first-page":"4793","DOI":"10.1109\/tnnls.2020.3027314","article-title":"A survey on explainable artificial intelligence (xai): Toward medical xai","volume":"32","author":"Tjoa","year":"2020","journal-title":"IEEE Trans. neural Netw. Learn. Syst."},{"key":"B39","first-page":"24","article-title":"Score-cam: Score-weighted visual explanations for convolutional neural networks","author":"Wang","year":"2020"},{"key":"B16","doi-asserted-by":"crossref","first-page":"337","DOI":"10.3233\/FAIA210362","article-title":"Human-centered concept explanations for neural networks","volume-title":"Neuro-symbolic artificial intelligence: The state of the art","author":"Yeh","year":"2021"},{"key":"B40","first-page":"268","article-title":"Privacy risk in machine learning: Analyzing the connection to overfitting","author":"Yeom","year":"2018"},{"key":"B41","first-page":"818","article-title":"Visualizing and understanding convolutional networks","author":"Zeiler","year":"2014"},{"key":"B42","first-page":"2921","article-title":"Learning deep features for discriminative localization","author":"Zhou","year":"2016"},{"key":"B43","first-page":"119","article-title":"Interpretable basis decomposition for visual explanation","author":"Zhou","year":"2018"}],"container-title":["Frontiers in Bioinformatics"],"original-title":[],"link":[{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fbinf.2023.1194993\/full","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,5]],"date-time":"2023-07-05T22:48:02Z","timestamp":1688597282000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.frontiersin.org\/articles\/10.3389\/fbinf.2023.1194993\/full"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,5]]},"references-count":43,"alternative-id":["10.3389\/fbinf.2023.1194993"],"URL":"https:\/\/doi.org\/10.3389\/fbinf.2023.1194993","relation":{},"ISSN":["2673-7647"],"issn-type":[{"value":"2673-7647","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7,5]]},"article-number":"1194993"}}