Pith. sign in

REVIEW 2 cited by

Does BERT Pretrained on Clinical Notes Reveal Sensitive Data?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2104.07762 v2 pith:M4CQWK27 submitted 2021-04-15 cs.CL cs.AIcs.LG

classification cs.CLcs.AIcs.LG
keywords bertclinicaldatamodelspretrainedreleasesensitivethey
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Large Transformers pretrained over clinical notes from Electronic Health Records (EHR) have afforded substantial gains in performance on predictive clinical tasks. The cost of training such models (and the necessity of data access to do so) coupled with their utility motivates parameter sharing, i.e., the release of pretrained models such as ClinicalBERT. While most efforts have used deidentified EHR, many researchers have access to large sets of sensitive, non-deidentified EHR with which they might train a BERT model (or similar). Would it be safe to release the weights of such a model if they did? In this work, we design a battery of approaches intended to recover Personal Health Information (PHI) from a trained BERT. Specifically, we attempt to recover patient names and conditions with which they are associated. We find that simple probing methods are not able to meaningfully extract sensitive information from BERT trained over the MIMIC-III corpus of EHR. However, more sophisticated "attacks" may succeed in doing so: To facilitate such research, we make our experimental setup and baseline probing models available at https://github.com/elehman16/exposing_patient_data_release

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. InputSnatch: Stealing Input in LLM Services via Timing Side-Channel Attacks

    cs.CR 2024-11 conditional novelty 6.0 of 10

    A timing side-channel on shared LLM caches can partially reconstruct private user inputs in prompt-engineering and RAG services.

  2. DMRL: Data- and Model-aware Reward Learning for Data Extraction

    cs.LG 2025-05 reject novelty 4.0 of 10

    DMRL applies inverse reinforcement learning with GRPO to train LLMs to extract PII, reporting higher reconstruction accuracy than four baselines on three datasets.

Pith tools