Differentially Private ECG Heartbeat Classification
Resumo
Automated heartbeat classification models have become crucial for modern cardiac monitoring and the early detection of cardiovascular diseases. However, these models’ tendency to memorize sensitive patient data poses a significant privacy risk. Differential Privacy (DP) has emerged as the mathematical foundation for providing formal, provable privacy guarantees during model training, effectively mitigating risks of data memorization. Despite its robustness, directly applying standard DP algorithms, such as DP-SGD, to neural networks often results in a significant drop in classification performance. We address this challenge by introducing DP-ECG-HC, a privatized architecture that leverages a Conformer-based, tokenized approach to extract morphological patterns from raw ECG signals. Experimental results on real-world ECG datasets demonstrate that DP-ECG-HC preserves robust model utility and effectively even under stringent privacy requirements, outperforming standard private deep learning baselines and achieving a superior privacy-utility trade-off.
Palavras-chave:
Conformer, Differential Privacy, DP-SGD, ECG Heartbeat Classification, Privacy-Utility Trade-off
Referências
Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., and Zhang, L. (2016). Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 308–318. ACM.
Agrawal, V., Kalmady, S. V., Malipeddi, V. M., Manthena, M. V., Sun, W., Islam, S., Hindle, A., Kaul, P., and Greiner, R. (2024). Federated learning and differential privacy techniques on multi-hospital population-scale electrocardiogram data. arXiv preprint arXiv:2405.00725.
Al-Jibreen, A., Al-Ahmadi, S., Islam, S., and Artoli, A. M. (2024). Person identification with arrhythmic ecg signals using deep convolution neural network. Scientific Reports, 14(1):4460.
Barni, M., Failla, P., Lazzeretti, R., Sadeghi, A.-R., and Schneider, T. (2011). Privacy-preserving ecg classification with branching programs and neural networks. IEEE Transactions on Information Forensics and Security, 6(2):452–468.
Cui, J., Wang, L., He, X., De Albuquerque, V. H. C., AlQahtani, S. A., and Hassan, M. M. (2021). Deep learning-based multidimensional feature fusion for classification of ecg arrhythmia. Neural Comput. Appl., 35(22):16073–16087.
Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. In Halevi, S. and Rabin, T., editors, Theory of Cryptography, pages 265–284. Springer Berlin Heidelberg.
Dwork, C. and Roth, A. (2014). The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci., 9(3–4):211–407.
ElKomy, O. M., Rushdy, E., Nasser, S., and Khashaba, M. M. (2025). Exploring differential privacy in cnns, lstms, grus, and rnns for heartbeat detection from multimodal data. Journal of Big Data, 12(1):216.
Ghazarian, A., Zheng, J., and Rakovski, C. (2024). Privacy-preserving ecg data analysis with differential privacy: A literature review and a case study. arXiv preprint arXiv:2406.13880.
Gulati, A., Qin, J., Chiu, C.-C., Parmar, N., Zhang, Y., Yu, J., Han, W., Wang, S., Zhang, Z., Wu, Y., and Pang, R. (2020). Conformer: Convolution-augmented transformer for speech recognition. In Proc. Interspeech 2020.
Khalid, N., Qayyum, A., Bilal, M., Al-Fuqaha, A., and Qadir, J. (2023). Privacy-preserving artificial intelligence in healthcare: Techniques and applications. Computers in Biology and Medicine, 158:106848.
Ma, C., Li, J., Ding, M., Liu, B., Wei, K., Weng, J., and Poor, H. V. (2023). Rdp-gan: A rényi-differential privacy based generative adversarial network. IEEE Transactions on Dependable and Secure Computing, 20(6):4838–4852.
Marouani, A., Siméoni, O., Jégou, H., Bojanowski, P., and Vo, H. V. (2025). Revisiting [cls] and patch token interaction in vision transformers. arXiv preprint.
Moura, L., Coutinho, E., Moreira, L., and Costa, I. (2024). Desafios do tratamento de dados da lgpd em aplicações web. In Anais do Workshop em Engenharia de Requisitos (WER24). UFC/ITA.
Nolin-Lapalme, A., Avram, R., and Julie, H. (2023). Privecg: generating private ecg for end-to-end anonymization. In Deshpande, K., Fiterau, M., Joshi, S., Lipton, Z., Ranganath, R., Urteaga, I., and Yeung, S., editors, Proceedings of the 8th Machine Learning for Healthcare Conference, volume 219 of Proceedings of Machine Learning Research, pages 509–528. PMLR.
Phang, K. and Kaabi, J. (2025). Privacy in flux: A 35-year systematic review of legal evolution, effectiveness, and global challenges (u.s./e.u. focus with international comparisons). Journal of Cybersecurity and Privacy, 5(4):103.
Pinto, J. R. and Cardoso, J. S. (2020). Explaining ecg biometrics: Is it all in the qrs? In 2020 International Conference of the Biometrics Special Interest Group (BIOSIG). IEEE.
Rafie, N., Kashou, A. H., and Noseworthy, P. A. (2021). Ecg interpretation: Clinical relevance, challenges, and advances. Hearts, 2(4):505–513.
Vásquez-Iturralde, F., Flores-Calero, M. J., Grijalva, F., and Rosales-Acosta, A. (2024). Automatic classification of cardiac arrhythmias using deep learning techniques: A systematic review. IEEE Access, 12.
Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, Ł., and Polosukhin, I. (2017). Attention is all you need. In 31st Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, CA, USA.
Zanchi, B., Monachino, G., Fiorillo, L., Conte, G., Auricchio, A., Tzovara, A., and Faraci, F. D. (2025). Synthetic ecg signals generation: A scoping review. Computers in Biology and Medicine, 184:109453.
Zhang, X. and Zhang, Q. (2025). Defending against attacks in deep learning with differential privacy: a survey. Artificial Intelligence Review, 58(347).
Agrawal, V., Kalmady, S. V., Malipeddi, V. M., Manthena, M. V., Sun, W., Islam, S., Hindle, A., Kaul, P., and Greiner, R. (2024). Federated learning and differential privacy techniques on multi-hospital population-scale electrocardiogram data. arXiv preprint arXiv:2405.00725.
Al-Jibreen, A., Al-Ahmadi, S., Islam, S., and Artoli, A. M. (2024). Person identification with arrhythmic ecg signals using deep convolution neural network. Scientific Reports, 14(1):4460.
Barni, M., Failla, P., Lazzeretti, R., Sadeghi, A.-R., and Schneider, T. (2011). Privacy-preserving ecg classification with branching programs and neural networks. IEEE Transactions on Information Forensics and Security, 6(2):452–468.
Cui, J., Wang, L., He, X., De Albuquerque, V. H. C., AlQahtani, S. A., and Hassan, M. M. (2021). Deep learning-based multidimensional feature fusion for classification of ecg arrhythmia. Neural Comput. Appl., 35(22):16073–16087.
Dwork, C., McSherry, F., Nissim, K., and Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. In Halevi, S. and Rabin, T., editors, Theory of Cryptography, pages 265–284. Springer Berlin Heidelberg.
Dwork, C. and Roth, A. (2014). The algorithmic foundations of differential privacy. Found. Trends Theor. Comput. Sci., 9(3–4):211–407.
ElKomy, O. M., Rushdy, E., Nasser, S., and Khashaba, M. M. (2025). Exploring differential privacy in cnns, lstms, grus, and rnns for heartbeat detection from multimodal data. Journal of Big Data, 12(1):216.
Ghazarian, A., Zheng, J., and Rakovski, C. (2024). Privacy-preserving ecg data analysis with differential privacy: A literature review and a case study. arXiv preprint arXiv:2406.13880.
Gulati, A., Qin, J., Chiu, C.-C., Parmar, N., Zhang, Y., Yu, J., Han, W., Wang, S., Zhang, Z., Wu, Y., and Pang, R. (2020). Conformer: Convolution-augmented transformer for speech recognition. In Proc. Interspeech 2020.
Khalid, N., Qayyum, A., Bilal, M., Al-Fuqaha, A., and Qadir, J. (2023). Privacy-preserving artificial intelligence in healthcare: Techniques and applications. Computers in Biology and Medicine, 158:106848.
Ma, C., Li, J., Ding, M., Liu, B., Wei, K., Weng, J., and Poor, H. V. (2023). Rdp-gan: A rényi-differential privacy based generative adversarial network. IEEE Transactions on Dependable and Secure Computing, 20(6):4838–4852.
Marouani, A., Siméoni, O., Jégou, H., Bojanowski, P., and Vo, H. V. (2025). Revisiting [cls] and patch token interaction in vision transformers. arXiv preprint.
Moura, L., Coutinho, E., Moreira, L., and Costa, I. (2024). Desafios do tratamento de dados da lgpd em aplicações web. In Anais do Workshop em Engenharia de Requisitos (WER24). UFC/ITA.
Nolin-Lapalme, A., Avram, R., and Julie, H. (2023). Privecg: generating private ecg for end-to-end anonymization. In Deshpande, K., Fiterau, M., Joshi, S., Lipton, Z., Ranganath, R., Urteaga, I., and Yeung, S., editors, Proceedings of the 8th Machine Learning for Healthcare Conference, volume 219 of Proceedings of Machine Learning Research, pages 509–528. PMLR.
Phang, K. and Kaabi, J. (2025). Privacy in flux: A 35-year systematic review of legal evolution, effectiveness, and global challenges (u.s./e.u. focus with international comparisons). Journal of Cybersecurity and Privacy, 5(4):103.
Pinto, J. R. and Cardoso, J. S. (2020). Explaining ecg biometrics: Is it all in the qrs? In 2020 International Conference of the Biometrics Special Interest Group (BIOSIG). IEEE.
Rafie, N., Kashou, A. H., and Noseworthy, P. A. (2021). Ecg interpretation: Clinical relevance, challenges, and advances. Hearts, 2(4):505–513.
Vásquez-Iturralde, F., Flores-Calero, M. J., Grijalva, F., and Rosales-Acosta, A. (2024). Automatic classification of cardiac arrhythmias using deep learning techniques: A systematic review. IEEE Access, 12.
Vaswani, A., Shazeer, N., Parmar, N., Uszkoreit, J., Jones, L., Gomez, A. N., Kaiser, Ł., and Polosukhin, I. (2017). Attention is all you need. In 31st Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, CA, USA.
Zanchi, B., Monachino, G., Fiorillo, L., Conte, G., Auricchio, A., Tzovara, A., and Faraci, F. D. (2025). Synthetic ecg signals generation: A scoping review. Computers in Biology and Medicine, 184:109453.
Zhang, X. and Zhang, Q. (2025). Defending against attacks in deep learning with differential privacy: a survey. Artificial Intelligence Review, 58(347).
Publicado
08/09/2026
Como Citar
SANTOS, João Volney; BRITO, Felipe Timbó; MACHADO, Javam de Castro.
Differentially Private ECG Heartbeat Classification. In: SIMPÓSIO BRASILEIRO DE BANCO DE DADOS (SBBD), 41. , 2026, São Carlos/SP.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 427-440.
ISSN 2763-8979.
DOI: https://doi.org/10.5753/sbbd.2026.249231.
