arXiv:2607.06037v1 [cs.CR] 7 Jul 2026
REAN: Reconstruction-aware ECG Anonymization Based on Privacy–Utility Orthogonality 1st Taerin Ki
2nd Sunghwan Park
3rd Junyoung Park
4th Jaewoo Lee
Chung-Ang University Seoul, South Korea [email protected]
Chung-Ang University Seoul, South Korea [email protected]
Chung-Ang University Seoul, South Korea [email protected]
Chung-Ang University Seoul, South Korea [email protected]
Abstract—A shared electrocardiogram (ECG) is itself a biometric fingerprint that can re-identify a patient and reveal personal information. Recent ECG anonymizers transform the signal before sharing to reduce privacy leakage. However, existing methods still face a privacy–utility trade-off, in which preserving privacy often compromises utility while preserving utility reveals personal information. We propose REAN (REconstruction-aware ECG ANonymizer), a raw ECG signal anonymizer, to address this privacy–utility trade-off. REAN reconstructs the signal using a 1-D U-Net trained with losses from frozen privacy and utility classifiers to reduce privacy leakage while preserving utility. The privacy and utility gradients are near-orthogonal (≈93.8◦ ), so reducing privacy leakage leaves utility almost unchanged. On four public PhysioNet databases, REAN achieves the strongest privacy–utility balance among raw ECG signal baselines. It drives re-identification to chance (0.96→0.00), keeps arrhythmia macroAUROC at the clean level (Clean 0.9982 vs. REAN 0.9991), and maintains re-identification protection under unseen privacyclassifier architectures. Index Terms—ECG Privacy, Anonymization, Privacy–Utility Trade-off, Signal Reconstruction, Gradient Orthogonality
I. I NTRODUCTION
ECG data
Attack
Privacy
Clean
0%
97.8%
REACT [5]
16%
81.8%
PP-VAE [6]
40%
11.0%
REAN
82%
97.4%
Utility
Fig. 1. The privacy–utility trade-off across ECG anonymizers. The lock marks how much identity and personal-information leakage the defense removes, and the hand marks the arrhythmia-diagnosis accuracy retained after anonymization, combined so that leaving any single attribute exposed keeps the score low. Only REAN scores high (green) on both axes.
suppressed along the privacy direction with almost no effect Electrocardiograms (ECGs) are widely shared for diagnosing on diagnosis. arrhythmia, ischemia, and conduction disorders, yet the same We propose REAN (REconstruction-aware ECG waveform is a biometric fingerprint that reveals a patient’s ANonymizer), a 1-D U-Net that exploits this geometry identity, gender, and age [1], [2]. Removing identifiers does and anonymizes an ECG in a single forward pass. REAN not protect the patient, because the waveform itself is a trains one objective that preserves diagnosis, protects privacy, quasi-identifier that enables re-identification from partial side and limits distortion, using a frozen diagnostic classifier and knowledge [3], [4]. An effective defense must therefore three frozen biometric classifiers as training signals. The transform the signal itself rather than its metadata. utility and privacy terms optimize together with little conflict, Transforming the signal faces a privacy–utility trade-off because their gradients are orthogonal. A learned residual between hiding biometric information and preserving diagnosis. conditioned on the input follows the privacy direction and Recent signal-level methods either degrade diagnosis or leave hides biometric information at little cost to diagnosis, whereas biometric information recoverable [5]–[8], because the two are blind noise moves the signal in every direction and harms entangled in the same morphology. This trade-off is usually diagnosis. This paper makes the following contributions. treated as the unavoidable price of anonymization. Fig. 1 shows this trade-off across existing anonymizers. We instead ask the • Privacy–utility orthogonality. We show that the utility central question of this paper. Can biometric information be and privacy directions are nearly orthogonal in ECG removed from an ECG without damaging the morphology that signal space, and use this geometry as the basis for diagnosis depends on? anonymization (Section II-B). We answer this question by observing that the utility and • The REAN anonymizer. We propose REAN, a classifierprivacy directions are nearly orthogonal in ECG signal space. guided 1-D U-Net that turns this geometry into a single Measured as input gradients, the two directions meet at about training objective and anonymizes a raw ECG waveform 89.8◦ (Section II-B). Biometric information can therefore be in a single forward pass (Section III).
R
1 T
P
Q S Fig. 2. ECG waveform for a normal cardiac cycle. Identity is carried mostly by the QRS shape, while arrhythmia diagnosis depends on rhythm and the broader P and T morphology.
•
Trade-off resolution on PhysioNet databases. REAN drives re-identification from 0.964 to chance while keeping arrhythmia macro-AUROC statistically indistinguishable from clean, and stays robust under purification and attackers unseen during training (Section IV-B). II. P RELIMINARY
A. The ECG signal An ECG carries both diagnostic and biometric information in the same waveform. The P–QRS–T morphology and the R–R interval are markers of arrhythmia, and the same shapes are person-specific enough to identify the patient (Fig. 2). Biometric information rests mostly on the person-specific QRS shape, whereas diagnosis depends on rhythm and the broader P and T morphology, so the two need not occupy the same part of the signal. We write an ECG as a signal window x ∈ RL and instantiate it at 250 Hz with 8-second windows (L=2000). The property we study does not depend on a specific L or sampling rate.
Util. +1.00 -0.08 -0.02 -0.01 ID -0.08 +1.00 +0.11 +0.08 0
Gen. -0.02 +0.11 +1.00 +0.20 Age -0.01 +0.08 +0.20 +1.00 Util.
ID
Gen.
1
Age
Fig. 3. Pairwise cosine between the parameter-space gradients of the utility (arrhythmia), ReID, gender, and age losses on clean ECG. Off-diagonals are near zero: the diagnostic gradient is near-orthogonal to every biometric gradient (utility vs. privacy ≈ 93.8◦ , cos ≈ −0.066). TABLE I ROBUSTNESS OF THE ORTHOGONALITY (4000 CLEAN WINDOWS , INPUT- GRADIENT ANGLE ). T HE UTILITY– PRIVACY ANGLE STAYS NEAR 90◦ ACROSS PROTECTED ATTRIBUTES AND ACROSS ATTACKER BACKBONES . Measurement
Angle
cos (95% CI)
80–100◦
Utility vs. privacy (bundled) Utility vs. identity Utility vs. gender Utility vs. age backbone: ResNet backbone: InceptionTime backbone: CNN-LSTM
89.8◦ 89.8◦ 89.95◦ 89.6◦ 89.5◦ 89.9◦ 89.5◦
0.003 (±0.002) 0.004 (±0.002) 0.001 (±0.002) 0.007 (±0.002) 0.008 (±0.004) 0.002 (±0.004) 0.008 (±0.003)
98.5% 98.0% 99.0% 98.8% 83.2% 86.1% 92.4%
B. Orthogonality of the utility and privacy directions The utility and privacy directions are nearly orthogonal in ECG signal space, and this geometry is what makes REAN possible. We establish it with frozen classifiers alone, before any anonymizer or training objective. For a signal window x ∈ RL , a frozen diagnostic classifier fdiag gives the utility loss Lutil = CE(fdiag (x), ydiag ), and frozen biometric classifiers fa for the protected attributes a ∈ A = {reid, gender, age} give the privacy loss X Lpriv = CE fa (x), ya . (1) a∈A
93.8◦ (cos ≈ −0.066) and the diagnostic gradient is nearorthogonal to every individual biometric gradient (Fig. 3). A near-90◦ angle is not meaningful on its own, since two random vectors in R2000 are already nearly orthogonal. What rules out coincidence is the causal consequence. Fullsignal Gaussian noise, which ignores this structure, collapses arrhythmia macro-AUROC to ≈ 0.62, whereas a perturbation along the privacy direction leaves diagnosis at the clean level (Section IV-B). This geometry sets two requirements for an anonymizer. An anonymizer should move the signal along the privacy direction, which suppresses biometric information at almost no cost to diagnosis (signal space), and it should optimize privacy and utility together, which their orthogonal gradients permit (parameter space). REAN meets both.
The utility and privacy directions are the input gradients ∇x Lutil and ∇x Lpriv , the directions that most change each loss. The two directions are near-orthogonal in signal space. On clean ECG the per-window angle between them averages about 89.8◦ (cosine 0.003), and every protected attribute shows the same pattern (89.6◦ –89.95◦ ). The angle stays stable across III. REAN: R ECONSTRUCTION - AWARE ECG A NONYMIZER 4000 windows (98.5% within 80◦ –100◦ ) and across biometric REAN anonymizes an ECG window in a single forward pass backbones (ResNet, InceptionTime, CNN-LSTM), as reported by exploiting the orthogonality of Section II-B (Fig. 4). We in Table I. The same orthogonality holds in the classifiers’ first design the training objective that suppresses biometrics parameter space, where ∇θ Lutil and ∇θ Lpriv meet at about without harming diagnosis (Section III-A), then realize it as a
1-D U-Net that reconstructs the waveform along the privacy direction (Section III-B).
in every direction at once, so it disturbs diagnosis and does not exploit this direction, whereas a residual conditioned on the input can align with it. REAN therefore reconstructs the A. Training objective signal with a U-Net rather than adding undirected noise. REAN trains a single objective with three terms that preserve The amplitude bound is selected to suppress protected diagnosis, suppress biometric information, and limit distortion. attributes without leaving the diagnostic-quality range. We The frozen diagnostic classifier fdiag scores diagnosis and the set εmax =0.08, the smallest validation-selected value at which three frozen biometric classifiers fa score biometric leakage; biometric inference reaches random-chance levels while PRD they never change during training and only score a candidate stays in the diagnostic-quality band [11]. REAN needs no peroutput x̂. With cross-entropy CE(·, ·), the utility loss is Lutil = signal detection or recalibration at inference; it conditions the CE(fdiag (x̂), ydiag ) and the privacy loss is the bundled Lpriv = perturbation on the input and produces it in one pass. CEbio of Eq. (1). The objective is Training and inference. Training updates only REAN, and inference uses only REAN. The three frozen biometric L = Lutil − Lpriv + D(x, x̂), (2) classifiers are ECGViT models and the frozen diagnostic where D(x, x̂) = PRD(x, x̂) + ∥x̂ − x∥1 limits distortion. The classifier is a 1-D ResNet [17]. REAN is trained with AdamW utility and distortion terms are minimized, while the privacy (lr=10−3 , wd=10−4 ) [18], cosine annealing [19], batch size 64, and 100 epochs on a balanced 30,000-window subsample; term is maximized through the minus sign. The three terms can be optimized together because their gra- the test set is never used for selection. At inference, a single dients are near-orthogonal. The minus sign on Lpriv raises the U-Net forward pass anonymizes each window independent of worry that ∇θ Lutil and ∇θ Lpriv subtract and leave little to train cohort statistics, which is why REAN is faster than per-sample on. Orthogonality rules this out. With ⟨∇θ Lutil , ∇θ Lpriv ⟩ ≈ 0 methods (Section IV-E). (Section II-B), changing the privacy loss shifts the diagnostic IV. E XPERIMENTS loss only through a first-order term that vanishes, so the two objectives behave as independent directions. The privacy–utility A. Setup trade-off is therefore escapable rather than fundamental, and Datasets. We evaluate REAN on a four-database PhysioNet REAN can suppress biometric information without sacrificing benchmark with 186 identities, of which 184 carry demographic diagnosis. labels (Table II). We resample all recordings to 250 Hz and We maximize correct-class cross-entropy rather than out- segment them into 8-second (2000-sample) windows with perput entropy. Maximizing correct-class cross-entropy directly window min-max normalization, producing 1,163,983 windows. reduces the true-class probability, whereas entropy can stay Arrhythmia labels are Normal (77.3%), AFIB (19.0%), PVC high even when the true class remains top-ranked. One privacy- (3.4%), and SVE (0.3%). All four models use the same perloss weight controls the bundled CEbio , matching the single participant temporal split (70/15/15) without segment overlap, near-orthogonal biometric direction of Section II-B. Each term so every subject appears in train, validation, and test partitions carries a nonnegative weight, selected on validation data by while time segments do not overlap. Identity is evaluated as Bayesian optimization with a Tree-structured Parzen Estima- closed-set re-identification with enrollment recordings, and tor [9] that approaches the ideal corner of privacy at chance, gender and age as attribute inference from unseen recordings utility maximal, and distortion minimal. The selected weights of cohort patients. A shared 500-window held-out set keeps the for utility, privacy, PRD, and L1 are (1.51, 0.153, 0.323, 1.46), baseline comparison fair while bounding REACT’s evaluation and nearby high-scoring configurations preserve the same cost; the set is gender-stratified (250/250) and preserves the privacy–utility–distortion pattern. arrhythmia distribution. Because REAN is amortized, we also evaluate Clean and REAN on a larger 20,000-window subset B. Reconstruction with a 1-D U-Net of the 177,329-window test split to test whether the REAN REAN realizes the objective as a 1-D U-Net that reconstructs trend persists at scale. the ECG by adding a bounded, input-conditioned residual. Frozen classifiers. Strong frozen classifiers define both the Given a window x ∈ RL , REAN outputs training signal and the privacy threat model. The three biometric classifiers are ECGViT models trained following the TransECG x̂ = x + tanh δθ (x) · εmax . (3) protocol [2] (patch 20, embedding 240, depth 6, 6 heads, MLP Here δθ is the residual predictor, implemented as a U-Net 128, stochastic depth survival 0.8), and the diagnostic classifier with an encoder–decoder structure, strided convolutions, skip is a 1-D ResNet. On clean data these models reach identity connections, base width C=32, and four resolution levels [10]. 0.964, gender 0.974, age 0.976, and arrhythmia 0.978. This The tanh bounds the residual to [−εmax , εmax ] and keeps x̂ strength matters because a weak biometric classifier would within the normalized signal range. overstate privacy. A learned residual is what lets REAN follow the privacy Baselines. We compare REAN with seven baselines under direction rather than move blindly. Section II-B shows that a identical data, models, and evaluation conditions. The baselines privacy direction exists that suppresses biometric information are full-signal Gaussian and Laplacian noise, REACT [5], while leaving diagnosis intact. Blind noise moves the signal Lee et al. [8], PP-VAE [6], PrivECG [7], and TransECG [2].
1
OBSERVATION: ORTHOGONALITY 𝛁𝑳𝒖𝒕𝒊𝒍 ≈ 90°
2
ORTHOGONALITY-AWARE OBJECTIVE
3
𝓛 = 𝓛𝒖𝒕𝒊𝒍 − 𝓛𝒑𝒓𝒊𝒗 + 𝑫
RECONSTRUCTION WITH CONSTRAINED RESIDUAL
Raw ECG
𝛁𝑳𝒑𝒓𝒊𝒗 Preserve Utility
Utility and Privacy gradients are nearly orthogonal
TRAINING
Anonymized ECG
𝜹
Suppress Preserve Identity Morphology
𝜹 ≤𝜺
Frozen Utility Classifier Arrhythmia
Raw ECG
Bounded Residual
1D U-Net
1D U-Net
Anonymized ECG
𝓛𝒖𝒕𝒊𝒍
⋯ Frozen Privacy Classifiers Identity
𝓛𝒑𝒓𝒊𝒗
+
Update Only U-Net
Gender Age
𝑫 (Distortion)
⋯
INFERENCE
Anonymized ECG
Raw ECG
REAN (Trained U-Net)
Single Forward Pass
Fig. 4. REAN framework, shown as three design steps above the training and inference pipelines. (1) On clean ECG the utility and privacy gradients ∇Lutil and ∇Lpriv are nearly orthogonal (≈ 90◦ ). (2) This geometry motivates a single orthogonality-aware objective L = Lutil − Lpriv + D that preserves diagnosis, suppresses biometric leakage, and limits distortion. (3) A 1-D U-Net reconstructs the waveform by adding a bounded, input-conditioned residual (Eq. 3), turning a raw ECG into an anonymized ECG. In training, a frozen utility classifier (arrhythmia) and three frozen privacy classifiers (identity, gender, age) score the anonymized output, and only the U-Net is updated. At inference, the trained U-Net anonymizes each window in a single forward pass. TABLE II P UBLIC DATABASES IN THE BENCHMARK ( ALL FROM P HYSIO N ET, RESAMPLED TO 250 H Z , 8- S WINDOWS ). S UBJECTS IS THE NUMBER OF SUBJECTS PER DATABASE (186 TOTAL ; 184 DEMOGRAPHICALLY LABELED ); AGE AND GENDER ARE AS REPORTED BY EACH SOURCE DATABASE . Database
Subjects
Age Range
Gender (M/F)
Sampling rate (Hz)
MIT-BIH Arrhythmia [12] MIT-BIH Long-Term [13] INCART [14], [15] SHDB-AF [16]
47 7 32 100
23–89 46–88 18–80 31–87
25/22 6/1 17/15 55/45
360 128 257 200
mixed arrhythmia long-term general monitoring coronary artery disease / arrhythmia atrial fibrillation
Total
186
→ 250
1.16 M windows
REACT is a reinforcement-learning method that re-optimizes noise per record with PPO [20]. Lee et al. finds identity-related feature regions with an attention mapper and perturbs a feature representation; because its native output is a feature rather than a signal, we preserve its attention-difference weighted noise mechanism and add a raw-to-feature encoder and feature-to-raw decoder so the input and output are raw waveforms. PP-VAE targets demographic privacy in a VAE latent space and does not address individual re-identification, and PrivECG generates an anonymized ECG with a GAN. TransECG is a re-identificationrisk analyzer rather than an anonymizer, so we instantiate its anonymization claim as a segment-noise baseline that injects Gaussian noise into the union of the QRS and P–R segments its attention ranks as most identifying. All methods use the same four frozen classifiers; learned baselines follow their
Health condition
paper’s optimizer and schedule, while TransECG, Gaussian, and Laplacian are training-free. Metrics. The benchmark measures privacy, diagnostic utility, distortion, and speed. Privacy is ReID accuracy, raw gender accuracy, and age accuracy, with random performance ≈0.005/0.500/0.200 (1/186, 1/2, 1/5); lower is better for ReID and age, and for binary gender the privacy-relevant quantity is the distance from 0.5, because a below-chance classifier is invertible by flipping its decision. Diagnostic utility (higher better) is arrhythmia accuracy and macro-AUROC, and macro-AUROC is preferred because SVE is only 0.3% of the data and weighted averaging would hide rare-class failure. Distortion (lower better) is PRD, which the compression literature considers “very good” below 9% [11]. Speed is anonymization time per window. An ideal method meets all
four requirements at once, as summarized by Table III and Fig. 6. B. Escaping the privacy–utility trade-off
Clean REACT
REAN is the only method that suppresses biometric leakage while keeping diagnosis at the clean level (Table III, Fig. 6). Against the pretrained attacker classifiers, REAN drives ReID PP-VAE and age accuracy to at or below chance and moves the raw gender prediction far from the clean response.1 REAN keeps arrhythmia macro-AUROC at the clean level. The point estimate is slightly higher than clean (0.9991 vs. 0.9982), but a paired REAN (ours) subject-clustered bootstrap gives a 95% confidence interval of [−0.0006, 0.0034] for REAN–Clean, so we read the difference as statistically indistinguishable rather than as an improvement. 0 1 2 3 4 5 6 7 The orthogonality is realized in training. From clean to Time (s) anonymized signals the diagnostic cross-entropy is essentially unchanged (0.075 → 0.076), while the biometric cross-entropies Fig. 5. Waveforms on a representative 8 s test window. Each panel overlays rise by over two orders of magnitude (ReID 0.23 → 42.6, gender the anonymized trace (color) on the clean signal (gray). REACT injects visible per-sample noise and PP-VAE collapses the morphology to a near-flat trace, 0.10 → 10.5, age 0.09 → 16.4). REAN drives the attackers’ loss whereas REAN closely tracks the clean waveform. Per-method distortion up steeply while paying almost no diagnostic cost, the direct (PRD) is reported in Table III. signature of optimizing a biometric objective whose gradient is orthogonal to the diagnostic one. TABLE III The baselines each trade off at least one axis. PP-VAE, M AIN RESULTS ON THE SHARED 500- WINDOW EVALUATION SET. B OLD MARKS THE BEST PRIVACY AND UTILITY VALUES AMONG random noise, TransECG, and REACT reduce leakage only PRIVACY- PROTECTIVE METHODS , EXCEPT FOR G ENDER ; PRD HAS NO by sacrificing utility or distortion, and Fig. 5 contrasts these WINNER MARKER . G ENDER IS RAW BINARY ACCURACY, SO distortions with REAN. PrivECG and Lee et al. [8] preserve BELOW- CHANCE VALUES ARE INVERTIBLE AND MUST BE READ BY DISTANCE FROM 0.5. REAN’ S AUROC IS INDISTINGUISHABLE FROM utility or waveform similarity but leave identity recoverable CLEAN ( PAIRED SUBJECT- CLUSTERED 95% CI: [−0.0006, 0.0034]). (0.966 and 0.882). The Lee et al. noise reduces its own attentionmapper identity head, yet the output stays re-identifiable by an Privacy Utility (↑) Distort. Method independent biometric classifier, which shows that anonymizing ReID↓ Gender Age↓ Arr AUROC PRD against oneself does not transfer to an independent attacker. The REAN trend persists at larger scale, so this REAN-only Clean (no def.) 0.964 0.974 0.976 0.978 0.9982 0.00 Random chance ≈.005 0.500 0.200 — — — check supports the shared 500-window comparison rather than replacing it. On a single 20,000-window subset of the test split, Noise-Gauss 0.058 0.572 0.304 0.770 0.6161 24.00 Noise-Lap 0.032 0.568 0.232 0.770 0.4653 33.70 Clean and REAN macro-AUROC are 0.9867 and 0.9945, and REACT [5] 0.210 0.584 0.462 0.818 0.9034 18.20 REAN attains ReID 0.00025, gender 0.488, age 0.082, and TransECG 0.250 0.610 0.478 0.754 0.8185 14.80 PRD 6.77%. C. Privacy robustness REAN’s re-identification protection holds under adaptive and unseen attacks. We test three threats stronger than the pretrained attackers of Section IV-B. Input purification. An attacker who receives the anonymized signal x̂ cannot restore identity by denoising. We apply Butterworth 40 Hz low-pass filtering, db4 wavelet soft thresholding, median filtering, Savitzky–Golay filtering, and a learned denoising autoencoder trained on clean ECG [21]–[24], applied only to REAN’s output. After purification, ReID stays at or near chance across all purifiers, while gender and age are partially recovered only by the stronger learned restorers (Table IV). If REAN’s residual δ were random high-frequency 1 Gender is binary, so the privacy-relevant quantity is the distance from chance (0.5), not whether raw accuracy is above or below 0.5; a below-chance classifier can be inverted by flipping the decision. We therefore report gender as raw binary accuracy for transparency, do not mark a gender winner in Table III, and treat retraining-aware recovery as the stronger gender test (Table VI).
PP-VAE [6] PrivECG [7] Lee et al. [8]
0.004 0.966 0.882
0.452 0.976 0.912
0.252 0.110 0.6389 0.978 0.980 0.9981 0.940 0.968 0.9975
11.91 0.30 3.17
REAN (ours)
0.000
0.142
0.044 0.974 0.9991
5.56
noise, purification would restore identity, so this result shows that δ is not removed by standard signal denoising. Unseen attacker architectures. REAN’s protection transfers to attackers it never trained against. REAN is trained against ECGViT biometric classifiers, so we re-attack the anonymized signal with 1-D ResNet, InceptionTime [25], and CNN-LSTM. Identity stays substantially reduced relative to clean while gender and age are partially recovered (gender 0.43–0.60, age 0.28–0.42), so ReID protection is not overfit to the trained architecture (Table V) and is consistent with the backboneinvariant orthogonality of Section II-B. Retraining-aware adversary. Residual biometric structure remains learnable to an adversary that retrains on anonymized
1.0
Noise-Lap PP-VAE
REAN (ours) ideal region
0.8
Noise-Gauss
REACT
TransECG
0.6
0.0
0.8
0.6
0.4
0.4 0.2
bubble size = PRD (%) 1
15
30
TABLE V ATTACKING THE ANONYMIZED SIGNAL WITH UNSEEN ARCHITECTURES . G ENDER FOLLOWS THE RAW- BINARY CAVEAT IN TABLE III.
0.2
Lee et al.
Relative speed (fastest = 1)
Privacy protection (1
leakage,
)
1.0
PrivECG
0.0 0.6 0.8 1.0 0.4 arrhythmia macro-AUROC ( ) Clinical utility Fig. 6. Privacy–utility–speed. x: arrhythmia macro-AUROC (↑); y: privacy protection (1−normalized leakage, ↑); bubble size: PRD (distortion); color: relative speed (fastest = 1; green fast, red slow). This aggregate uses the raw leakage metrics in Table III; the binary-gender inversion caveat is reported separately in the table caption. REAN reaches the high-utility, high-protection corner while staying in the fast amortized band. TABLE IV ATTRIBUTE RECOVERY AFTER APPLYING A PURIFIER TO REAN’ S OUTPUT. L OWER R E ID/AGE IS MORE ROBUST; G ENDER FOLLOWS THE RAW- BINARY CAVEAT IN TABLE III. “PRD→ CLEAN ” IS DISTANCE FROM THE ORIGINAL . Purifier
ReID
Gender
Age
PRD→clean
Clean (recovery bound) Random chance REAN (no purify)
0.964 ≈.005 0.000
0.974 0.500 0.142
0.976 0.200 0.044
0.00 — 5.56
Low-pass 40 Hz Wavelet (db4) Median filter Savitzky–Golay DAE (learned)
0.000 0.000 0.000 0.012 0.036
0.174 0.166 0.176 0.474 0.560
0.046 0.048 0.058 0.198 0.398
5.14 5.12 5.19 5.42 6.80
Attacker
ReID
Gender
Age
Random
≈.005
0.500
0.200
ResNet1D InceptionTime CNN-LSTM
0.092 0.026 0.050
0.580 0.432 0.598
0.422 0.276 0.288
TABLE VI R ETRAINING - AWARE ATTACK : THE ATTACKER RETRAINS A BIOMETRIC CLASSIFIER AS THE SHARE OF ANONYMIZED DATA GROWS . G ENDER FOLLOWS THE RAW- BINARY CAVEAT IN TABLE III. Training mix
ReID
Gender
Age
20% anon + 80% clean 50% anon + 50% clean 100% anon
0.590 0.726 0.886
0.614 0.818 0.938
0.672 0.702 0.840
show the REAN–Clean macro-AUROC estimate stabilizing as the sample grows, reaching 0.9972 for REAN against 0.9956 for clean. An SVE-enriched balanced evaluation using all 469 SVE windows and 469 windows from each other class (1,876 windows, 162 subjects) gives the same picture, with macroAUROC 0.9977 against clean 0.9930 and SVE AUROC 0.9977 against clean 0.9842. These checks confirm that the utility result is not a sample-size or rare-class artifact.
E. Ablation and speed
No single objective term is sufficient for the privacy–utility– distortion balance (Table VIII). Turning the three bundled terms (U, P, D) on and off separates their roles. Single-term objectives each fail, since U leaks identity, P harms diagnosis, and D preserves the input without protection. Pairwise objectives remove one failure but leave another, since U P distorts, P D hurts diagnosis, and U D leaks. Only the full objective (U P D) data. Recovery grows with the anonymized-data share: ReID satisfies every requirement at once, reaching identity at chance, rises from 0.000 to 0.590 at a 20% mix, 0.726 at 50%, and arrhythmia 0.974, and PRD 5.56, and it attains the smallest 0.886 at 100% (Table VI). The 100% setting is a worst case distance to the ideal corner (d=0.28). that requires a fully labeled anonymized corpus, and read as Speed. As a secondary benefit, REAN is fast because it an upper bound it shows that a deterministic map can leave anonymizes in a single forward pass. The speed comes from residual biometric structure. This is a structural property of amortization, not from the orthogonality, since REAN runs any deterministic anonymizer, which we discuss in Section VI. the U-Net once per window with no per-record optimization. We measure GPU latency on an RTX 4090 (PyTorch 2.11.0, D. Diagnostic utility CUDA 13.0), timing anonymized-signal generation on the REAN preserves diagnostic utility across arrhythmia classes same 256-window batch with GPU synchronization. REAN and at natural prevalence. On the shared comparison set, per- takes 0.117 ms/window, within the amortized band below class AUROC stays near clean for all four classes, and macro- 1 ms/window, whereas REACT takes 12.73 ms/window (108.8× AUROC (the mean of the four one-vs-rest class AUROCs) REAN) because it re-optimizes per record. The other fast matches Table III (Table VII). methods each fail a different requirement. PrivECG leaves We further validate the rare SVE class beyond the shared identity recoverable, PP-VAE collapses utility, TransECG 500-window set. On a natural-prevalence 20,000-window pool damages utility, and Lee et al. does not return a reusable (183 subjects, 54 SVE windows), 30 stratified resamplings raw waveform.
TABLE VII P ER - CLASS ARRHYTHMIA AUROC (SVE IS 0.3% OF THE TEST SPLIT ). REAN ( OURS ) LAST; M ACRO IS THE MEAN OVER THE FOUR CLASSES . Method
Normal
PVC
SVE
AFIB
Macro
Clean Noise-Gauss Noise-Lap REACT [5] TransECG PP-VAE [6] PrivECG [7] Lee et al. [8]
0.9963 0.5601 0.4681 0.8804 0.7605 0.5372 0.9962 0.9943
1.0000 0.7356 0.6088 0.9885 0.8679 0.7651 1.0000 0.9988
1.0000 0.6473 0.3006 0.8297 0.9559 0.6012 1.0000 1.0000
0.9963 0.5212 0.4839 0.9149 0.6895 0.6521 0.9961 0.9970
0.9982 0.6161 0.4653 0.9034 0.8185 0.6389 0.9981 0.9975
REAN (ours)
0.9978
0.9997
1.0000
0.9990
0.9991
TABLE VIII O BJECTIVE ABLATION (U=U TILITY, P=P RIVACY, D=D ISTORTION ). REAN (UPD) LAST. d IS THE DISTANCE TO THE IDEAL CORNER ( MEAN PRIVACY LEAKAGE + UTILITY GAP + PRD/20; LOWER BETTER ). G ENDER FOLLOWS THE RAW- BINARY CAVEAT IN TABLE III. Terms ReID Gender
Age
Arr-Acc PRD%
d↓
U P D UP UD PD
0.704 0.000 0.964 0.000 0.964 0.000
0.830 0.094 0.974 0.096 0.974 0.146
0.842 0.104 0.976 0.074 0.976 0.016
0.990 0.730 0.978 0.962 0.978 0.810
10.27 15.45 0.00 15.59 0.00 5.65
1.29 1.02 1.00 0.80 1.00 0.45
U P D 0.000
0.142
0.044
0.974
5.56
0.28
VI. D ISCUSSION Why orthogonality exists. Orthogonality likely arises because identity and arrhythmia rely on different ECG substructures. Identity is carried mostly by the person-specific shape of the QRS complex, while arrhythmia diagnosis depends on rhythm and broader P and T morphology. These different signal dependencies make the direction that blurs identity nearly orthogonal to the direction that determines diagnosis, and REAN learns this structure from frozen-model gradients without an explicit rule. Limitations. REAN’s central privacy limitation is deterministic leakage under a retraining-aware adversary. For a deterministic map x 7→ x̂ and a biometric attribute ya , the dataprocessing inequality [27] gives I(x̂; ya ) ≤ I(x; ya ) rather than equality, so residual biometric structure can remain and be recovered by retraining (Section IV-C). Formal control of this leakage requires stochastic mechanisms such as differential privacy [26], [28] or a variational bottleneck [29], so REAN is best viewed as practical signal-level obfuscation rather than formal irreversible anonymization. A second limitation is evaluation scope, since our evaluation uses single-lead ECG with a within-subject temporal split, leaving multi-lead and 12-lead recordings, unseen-subject deployment, and nonarrhythmia clinical domains to future work. VII. C ONCLUSION
We proposed REAN, a raw ECG waveform anonymizer for privacy-preserving ECG sharing. The central obstacle V. R ELATED W ORK was the privacy–utility trade-off, since anonymization must ECG-based biometrics. ECG biometrics make signal-level suppress biometric information without destroying diagnostic defenses necessary. Fiducial and deep models identify people morphology. We showed that this trade-off is escapable because and infer attributes from ECG signals [1], [2], and partial side the diagnostic and biometric objectives have near-orthogonal knowledge can re-identify public ECG records [3], [4]. REAN gradients, and REAN turned this geometry into a lightweight therefore evaluates against strong biometric classifiers. learned transform. Using frozen diagnostic and biometric Anonymization defenses address complementary deploy- classifiers only during training, REAN learned a single-pass ment settings. Feature- and latent-space transforms are attractive U-Net anonymizer that suppresses biometric leakage while when the downstream extractor is fixed, because they can be fast preserving diagnosis. On four PhysioNet databases, REAN and compact. Lee et al. [8] perturbs identity-related features, but drove re-identification to chance, kept arrhythmia diagnosis at its native output is extractor-tied and stays re-identifiable after the clean level, and transferred re-identification protection to our raw-waveform bridge. PP-VAE [6] targets demographic unseen attacker architectures, at over an order of magnitude less privacy in a latent representation, but its representative-beat time than per-sample optimization. The remaining challenge is output does not preserve the rhythm information the arrhythmia retraining-aware leakage, and future work should add stochastic task needs. mechanisms and extend evaluation to multi-lead and multiSignal-space defenses return deployable waveforms, but they domain settings. trade off speed, privacy, and diagnostic fidelity in different R EFERENCES ways. PrivECG [7] keeps high signal fidelity but leaves strong biometric classifiers accurate in our benchmark. Iterative [1] Z. Wang, A. Kanduri, S. A. H. Aqajari, S. Jafarlou, S. R. Mousavi, P. Liljeberg, S. Malik, and A. M. Rahmani, “Ecg unveiled: Analysis of methods such as REACT [5] optimize protection per record, client re-identification risks in real-world ecg datasets,” in 2024 IEEE but their per-sample optimization makes large-scale deployment 20th International Conference on Body Sensor Networks (BSN), pp. 1–4, slow. Full-signal noise and differential privacy [26] are fast, but IEEE, 2024. perturb diagnostic morphology without using the diagnostic– [2] Z. Wang, E. Khatibi, K. Kazemi, I. Azimi, S. Mousavi, S. Malik, and A. M. Rahmani, “Transecg: Leveraging transformers for explainable ecg biometric geometry. re-identification risk analysis,” arXiv preprint arXiv:2503.13495, 2025. Position of REAN. REAN combines reusable raw ECG [3] Z. Wang, E. Khatibi, F. Firouzi, S. R. Mousavi, K. Chakrabarty, and A. M. Rahmani, “Linkage attacks expose identity risks in public ecg output, a multi-attribute privacy loss, and a geometric basis data sharing,” in 2025 47th Annual International Conference of the IEEE for preserving diagnosis while suppressing biometrics, with Engineering in Medicine and Biology Society (EMBC), pp. 1–7, IEEE, single-pass speed as a secondary benefit. 2025.
[4] H. Aguelal and P. Palmieri, “Ecg de-anonymization: Real-world risks and a privacy-by-design mitigation strategy,” in 2025 IEEE 38th International Symposium on Computer-Based Medical Systems (CBMS), pp. 449–456, IEEE, 2025. [5] A. Datta, T. Bhattacharyya, E. Khatibi, A. Seth, Z. Wang, S. R. Mousavi, A. M. Rahmani, F. Firouzi, and K. Chakrabarty, “React: Reinforcement learning-based adaptive ecg anonymization and privacy threat mitigation,” in 2025 IEEE International Conference on Omni-layer Intelligent Systems (COINS), pp. 1–8, IEEE, 2025. [6] F. S. Shishir, C. J. Harvey, A. Gupta, A. Noheria, and S. Shomaji, “Aienabled privacy-preserving cardiac diagnostics via electrocardiograms,” Scientific Reports, 2026. [7] A. Nolin-Lapalme, R. Avram, and H. Julie, “Privecg: Generating private ecg for end-to-end anonymization,” in Machine Learning for Healthcare Conference, pp. 509–528, PMLR, 2023. [8] H. Lee, M. Kim, and Y. D. Chung, “Privacy-preserving ecg data collection for arrhythmia classification,” Biomedical Signal Processing and Control, vol. 112, p. 108374, 2026. [9] J. Bergstra, R. Bardenet, Y. Bengio, and B. Kégl, “Algorithms for hyperparameter optimization,” Advances in neural information processing systems, vol. 24, 2011. [10] O. Ronneberger, P. Fischer, and T. Brox, “U-net: Convolutional networks for biomedical image segmentation,” in International Conference on Medical image computing and computer-assisted intervention, pp. 234– 241, Springer, 2015. [11] Y. Zigel, A. Cohen, and A. Katz, “The weighted diagnostic distortion (wdd) measure for ecg signal compression,” IEEE transactions on biomedical engineering, vol. 47, no. 11, pp. 1422–1430, 2000. [12] G. B. Moody and R. G. Mark, “The impact of the mit-bih arrhythmia database,” IEEE engineering in medicine and biology magazine, vol. 20, no. 3, pp. 45–50, 2001. [13] A. L. Goldberger, L. A. N. Amaral, L. Glass, J. M. Hausdorff, P. C. Ivanov, R. G. Mark, J. E. Mietus, G. B. Moody, C.-K. Peng, and H. E. Stanley, “Physiobank, physiotoolkit, and physionet: Components of a new research resource for complex physiologic signals,” Circulation, vol. 101, no. 23, pp. e215–e220, 2000. RRID:SCR 007345. [14] V. Tihonenko, A. Khaustov, S. Ivanov, A. Rivin, and E. Yakushenko, “St petersburg incart 12-lead arrhythmia database. 2008,” PhysioBank PhysioToolkit and PhysioNet, 2008. [15] A. L. Goldberger, L. A. Amaral, L. Glass, J. M. Hausdorff, P. C. Ivanov, R. G. Mark, J. E. Mietus, G. B. Moody, C.-K. Peng, and H. E. Stanley, “Physiobank, physiotoolkit, and physionet: components of a new research resource for complex physiologic signals,” circulation, vol. 101, no. 23, pp. e215–e220, 2000. [16] K. Tsutsui, S. B. Brimer, N. Ben-Moshe, J. M. Sellal, J. Oster, H. Mori, Y. Ikeda, T. Arai, S. Nakano, R. Kato, et al., “Shdb-af: a japanese holter ecg database of atrial fibrillation,” Scientific data, vol. 12, no. 1, p. 454, 2025. [17] K. He, X. Zhang, S. Ren, and J. Sun, “Deep residual learning for image recognition,” in Proceedings of the IEEE conference on computer vision and pattern recognition, pp. 770–778, 2016. [18] I. Loshchilov and F. Hutter, “Decoupled weight decay regularization,” arXiv preprint arXiv:1711.05101, 2017. [19] I. Loshchilov and F. Hutter, “SGDR: Stochastic gradient descent with warm restarts,” in Proc. Int. Conf. Learning Representations (ICLR), 2017. arXiv:1608.03983. [20] J. Schulman, F. Wolski, P. Dhariwal, A. Radford, and O. Klimov, “Proximal policy optimization algorithms,” arXiv preprint arXiv:1707.06347, 2017. [21] S. Butterworth et al., “On the theory of filter amplifiers,” Wireless Engineer, vol. 7, no. 6, pp. 536–541, 1930. [22] D. L. Donoho, “De-noising by soft-thresholding,” IEEE transactions on information theory, vol. 41, no. 3, pp. 613–627, 1995. [23] A. Savitzky and M. J. Golay, “Smoothing and differentiation of data by simplified least squares procedures.,” Analytical chemistry, vol. 36, no. 8, pp. 1627–1639, 1964. [24] P. Vincent, H. Larochelle, Y. Bengio, and P.-A. Manzagol, “Extracting and composing robust features with denoising autoencoders,” in Proceedings of the 25th international conference on Machine learning, pp. 1096–1103, 2008. [25] H. Ismail Fawaz, B. Lucas, G. Forestier, C. Pelletier, D. F. Schmidt, J. Weber, G. I. Webb, L. Idoumghar, P.-A. Muller, and F. Petitjean, “Inceptiontime: Finding alexnet for time series classification,” Data mining and knowledge discovery, vol. 34, no. 6, pp. 1936–1962, 2020.
[26] A. Ghazarian, J. Zheng, and C. Rakovski, “Privacy-preserving ecg data analysis with differential privacy: A literature review and a case study,” arXiv preprint arXiv:2406.13880, 2024. [27] T. M. Cover and J. A. Thomas, Elements of information theory (wiley series in telecommunications and signal processing). Wiley-interscience, 2006. [28] C. Dwork, F. McSherry, K. Nissim, and A. Smith, “Calibrating noise to sensitivity in private data analysis,” in Theory of cryptography conference, pp. 265–284, Springer, 2006. [29] A. A. Alemi, I. Fischer, J. V. Dillon, and K. Murphy, “Deep variational information bottleneck,” in Proc. Int. Conf. Learning Representations (ICLR), 2017. arXiv:1612.00410.