🤖 AI Summary
This study addresses the privacy leakage risks arising from quasi-identifier accumulation when local medical large language models consult remote services. To mitigate this, we propose a privacy-aware self-evolving multi-agent system that manages clinical workflows through a local-remote collaborative architecture. The framework incorporates a full-dialogue-based privacy evaluation mechanism coupled with a reinforcement learning strategy to dynamically balance diagnostic accuracy against privacy risks. Furthermore, an unsupervised local curriculum memory module is constructed to enable efficient reuse of expert knowledge. Experimental results demonstrate that the proposed approach improves task accuracy by 15.8%, reduces personal detail disclosure rates to 0.2%, and eliminates re-identification risks entirely.
📝 Abstract
Clinical large language model (LLM) agents deployed locally can consult more capable remote models, but doing so risks exposing patient information. Privacy-conscious delegation places disclosure decisions with a local agent, yet removing explicit identifiers is insufficient: quasi-identifiers can accumulate across multi-turn consultations and repeated patient visits to enable re-identification. We introduce PrivMeSA, a privacy-aware self-evolving multi-agent system that learns to control disclosure and retains remote expertise for local reuse. A local agent manages each encounter and consults remote specialists that may request additional information. Reinforcement learning balances task accuracy against direct disclosure and registry-based re-identification risk, with privacy evaluated over the complete outbound transcript of each encounter. A local lesson memory distills completed consultations into generalized clinical guidance and retrieves relevant lessons before transmission, allowing subsequent cases to reuse expertise without another remote exchange. Memory grows without additional outcome labels or parameter updates. On an emergency-department benchmark built from MIMIC-IV-ED records, PrivMeSA improves mean task accuracy over delegation by up to 15.8 percentage points. In the same setting, PrivMeSA reduces the disclosure of personal details from 98.0% to 0.2% of cases and the share of cases in which the patient can be narrowed to ten or fewer registry patients from 74% to 0%.