IP Library › Granted Patent US 12,321,484
Granted Patent B2
US 12,321,484 · App. 17/676,140 · Granted Jun 3, 2025

Hybrid human-machine differential privacy

Inventors: Omer Dror (Sunnyvale, CA); Ofir Farchy (Modiin, IL)
Assignee: LYNX MD LTD.
G06F21/6245G06F21/6209G06F21/6254G06F21/6272G16H10/60G16H40/20G16H40/63G16H40/67
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,321,484
App. No.
17/676,140
Granted
Jun 3, 2025
Kind
B2
Abstract

Systems, methods and non-transitory computer readable media for hybrid differential privacy are provided. Queries associated with medical data may be received. The medical data may be accessed to determine a possible response to queries. Privacy loss levels associated with the possible responses may be determined. Confidence levels for the determinations of the privacy loss levels may be determined. Based on the privacy loss level and the confidence level corresponding to a particular possible response, it may be determine whether to provide the particular possible response, to avoid providing the particular possible response, or to involve manual review in a determination of whether to provide or to avoid providing the particular possible response.

Claims (54)

1. A non-transitory computer readable medium storing a software program comprising data and computer implementable instructions that when executed by at least one processor cause the at least one processor to perform a method for hybrid human-machine differential privacy, the method comprising:

receiving a first query, a second query and a third query associated with medical data from computing devices;

accessing the medical data stored on memory to determine a possible response to the first query, a possible response to the second query, and a possible response to the third query;

using a trained machine learning model to determine a first privacy loss level associated with the possible response to the first query, a second privacy loss level associated with the possible response to the second query, and a third privacy loss level associated with the possible response to the third query, wherein the first privacy loss level and the second privacy loss level are identical, wherein the trained machine learning model includes an interference model, a regression model, a clustering model, a classification algorithm, an image segmentation model, or an object detector;

using an output of the trained machine learning model to determine a first confidence level for the determination of the first privacy loss level, and a second confidence level for the determination of the second privacy loss level, wherein the second confidence level is lower than the first confidence level;

in response to the first privacy loss level and the first confidence level, providing the possible response to the first query;

in response to the third privacy loss level, avoiding providing the possible response to the third query; and

in response to the second privacy loss level and the second confidence level:

providing to a user information indicative of at least one aspect of the possible response to the second query,

receiving an input from the user, and

determining whether to provide or to avoid providing the possible response to the second query based on the input received from the user.

2. The non-transitory computer readable medium of claim 1 , wherein the method further comprises, in response to the input received from of the user, providing an alternative response to the second query.

3. The non-transitory computer readable medium of claim 2 , wherein the alternative response to the second query is based on the input received from the user.

4. The non-transitory computer readable medium of claim 3 , wherein the alternative response to the second query is selected by the user from a plurality of optional responses to the second query.

5. The non-transitory computer readable medium of claim 1 , wherein the first privacy loss level is based on a source of the first query, the second privacy loss level is based on a source of the second query, and the third privacy loss level is based on a source of the third query.

6. The non-transitory computer readable medium of claim 1 , wherein the first privacy loss level is based on historic queries associated with a source of the first query.

7. The non-transitory computer readable medium of claim 1 , wherein the first privacy loss level is based on responses to historic queries associated with a source of the first query.

8. The non-transitory computer readable medium of claim 1 , wherein the user is selected of a plurality of alternative users based on the second query.

9. The non-transitory computer readable medium of claim 1 , wherein the user is selected of a plurality of alternative users based on the possible response to the second query.

10. The non-transitory computer readable medium of claim 1 , wherein the user is selected of a plurality of alternative users based on a source of the second query.

11. The non-transitory computer readable medium of claim 1 , wherein the method further comprises:

receiving a fourth query associated with the medical data;

accessing the medical data to determine a possible response to the fourth query;

determining a fourth privacy loss level associated with the possible response to the fourth query, wherein the fourth privacy loss level is identical to the first privacy loss level and the second privacy loss level;

determining a fourth confidence level for the determination of the fourth privacy loss level, wherein the fourth confidence level is between the second confidence level and the first confidence level;

accessing users availability data; and

in response to the fourth privacy loss level and the fourth confidence level, determining based on the users availability data whether to involve manual review in a determination of whether to provide or to avoid providing the possible response to the fourth query.

12. The non-transitory computer readable medium of claim 1 , wherein the second query is received after the providence of the possible response to the first query, and the determination of the second confidence level is based on the possible response to the first query.

13. The non-transitory computer readable medium of claim 1 , wherein the first query and the second query are identical, the possible response to the first query and the possible response to the second query are identical, and the second confidence level is lower than the first confidence level due to the second query being received after the providence of the possible response to the first query.

14. The non-transitory computer readable medium of claim 1 , wherein the determination of the first confidence level is based on a source of the first query, the determination of the second confidence level is based on a source of the second query, and the determination of the third confidence level is based on a source of the third query.

15. The non-transitory computer readable medium of claim 1 , wherein the possible response to the second query includes an image, and the determination of the second confidence level is based on a result value of a calculated convolution of the image.

16. The non-transitory computer readable medium of claim 1 , wherein the possible response to the second query includes a plurality of elements, and the at least one aspect of the possible response to the second query is a distribution of the plurality of elements.

17. The non-transitory computer readable medium of claim 1 , wherein the possible response to the second query includes an image, and the at least one aspect of the possible response to the second query is based on a result value of a calculated convolution of the image.

18. A system for hybrid human-machine differential privacy, the system comprising:

at least one processing unit configured to:

receive a first query, a second query and a third query associated with medical data from computing devices;

access the medical data stored on memory to determine a possible response to the first query, a possible response to the second query, and a possible response to the third query;

using a trained machine learning model to determine a first privacy loss level associated with the possible response to the first query, a second privacy loss level associated with the possible response to the second query, and a third privacy loss level associated with the possible response to the third query, wherein the first privacy loss level and the second privacy loss level are identical;

using an output of the trained machine learning model to determine a first confidence level for the determination of the first privacy loss level, and a second confidence level for the determination of the second privacy loss level, wherein the second confidence level is lower than the first confidence level, wherein the trained machine learning model includes an interference model, a regression model, a clustering model, a classification algorithm, an image segmentation model, or an object detector;

in response to the first privacy loss level and the first confidence level, provide the possible response to the first query;

in response to the third privacy loss level, avoid providing the possible response to the third query; and

in response to the second privacy loss level and the second confidence level:

provide to a user information indicative of at least one aspect of the possible response to the second query,

receiving an input from the user, and

determine whether to provide or to avoid providing the possible response to the second query based on the input received from the user.

19. A method for hybrid human-machine differential privacy, the method comprising:

receiving a first query, a second query and a third query associated with medical data from computing devices;

accessing the medical data stored on memory to determine a possible response to the first query, a possible response to the second query, and a possible response to the third query;

using a trained machine learning model to determine a first privacy loss level associated with the possible response to the first query, a second privacy loss level associated with the possible response to the second query, and a third privacy loss level associated with the possible response to the third query, wherein the first privacy loss level and the second privacy loss level are identical, wherein the trained machine learning model includes an interference model, a regression model, a clustering model, a classification algorithm, an image segmentation model, or an object detector;

using an output of the trained machine learning model to determine a first confidence level for the determination of the first privacy loss level, and a second confidence level for the determination of the second privacy loss level, wherein the second confidence level is lower than the first confidence level;

in response to the first privacy loss level and the first confidence level, providing the possible response to the first query;

in response to the third privacy loss level, avoiding providing the possible response to the third query; and

in response to the second privacy loss level and the second confidence level:

providing to a user information indicative of at least one aspect of the possible response to the second query, receiving an input from the user, and determining whether to provide or to avoid providing the possible response to the second query based on the input received from the user.

Assignments (2)
SECURITY INTEREST Recorded Nov 11, 2022
From: LYNX MD LTD.
To: SILICON VALLEY BANK
Reel/Frame 061730/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 18, 2022
From: DROR, OMER; FARCHY, OFIR
To: LYNX MD LTD
Reel/Frame 059305/0991 →
Continuity (4)
Provisional Application 63151748 · Feb 21, 2021
Provisional Application 63151751 · Feb 21, 2021
Provisional Application 63151745 · Feb 21, 2021
Related Publication 20220171878A1 · Jun 2, 2022
References Cited (12)
US 8275632B2 · Awaraji · 2012 [cited by examiner]
US 12211598B1 · Aravamudan · 2025 [cited by examiner]
US 20060155668A1 · Miller · 2006 [cited by examiner]
US 20080172737A1 · Shen · 2008 [cited by examiner]
US 20120331567A1 · Shelton · 2012 [cited by examiner]
US 20130006865A1 · Spates · 2013 [cited by examiner]
US 20140136239A1 · Miller · 2014 [cited by examiner]
US 20140283091A1 · Zhang · 2014 [cited by examiner]
US 20150154357A1 · Biswas · 2015 [cited by examiner]
US 20170093926A1 · Chan · 2017 [cited by examiner]
US 20180082020A1 · Rajagopal · 2018 [cited by examiner]
US 20190087603A1 · Dror · 2019 [cited by examiner]