PRISM-DP: Privacy-Resilient Infinite-Sequence Memory via Martingale-Based Differential Privacy Composition for Continual Autoencoder Learning in Medical IoT
Research Article  ·  Published: 26 September 2026
Issue cover
Biomedical Informatics and Smart Healthcare
Volume 2, Issue 3, 2026: 136-151
Research Article Open Access

PRISM-DP: Privacy-Resilient Infinite-Sequence Memory via Martingale-Based Differential Privacy Composition for Continual Autoencoder Learning in Medical IoT

1 Computer Science and Engineering Department, Pragati University, Surampalem 533437, India
2 Computer Science and Engineering (AI & ML) Department, Pragati University, Surampalem 533437, India
* Corresponding Author: Manas Kumar Yogi, [email protected]
Volume 2, Issue 3
You have full access to this open access article · CC BY 4.0 License

Article Information

Abstract

Rehearsal-based continual learning in Medical IoT (MIoT) autoencoders requires replaying latent codes of past clinical tasks to prevent catastrophic forgetting. When these latent codes are derived from patient data, each replay constitutes a fresh privacy query, and existing differential privacy (DP) composition theorems-designed for finite, pre-specified query sequences-fail to bound cumulative privacy leakage over an unbounded task horizon. This paper presents PRISM-DP, a Privacy-Resilient Infinite-Sequence Memory framework that introduces a martingale-based DP composition theorem for unbounded replay sequences. PRISM-DP proves that a geometrically decaying per-task privacy schedule combined with a replay correlation decoupling lemma yields a convergent total privacy leakage bound for continual autoencoders. A privacy-amplified replay subsampling mechanism further tightens the per-replay leakage. Evaluated across 10 sequential clinical tasks on the PTB-XL, OhioT1DM, MIMIC-III Waveform, and WESAD datasets, PRISM-DP achieves an average AUC-ROC of 0.871, a backward transfer of $-0.055$, and keeps the total privacy budget within $\varepsilon=0.667$ at $\varepsilon_{\mathrm{cap}}=1.0$, outperforming all DP-certified baselines while providing a formally certified privacy guarantee for infinite-horizon continual MIoT learning.

Graphical Abstract

PRISM-DP: Privacy-Resilient Infinite-Sequence Memory via Martingale-Based Differential Privacy Composition for Continual Autoencoder Learning in Medical IoT

Keywords

continual learning differential privacy Medical IoT autoencoder martingale composition unbounded task sequence latent replay R\'enyi DP PTB-XL OhioT1DM

Data Availability Statement

The datasets analysed in this study are publicly available: PTB-XL and the MIMIC-III Waveform Database from PhysioNet (MIMIC-III under credentialed access and a data use agreement), OhioT1DM from Ohio University under a data use agreement, and WESAD from its authors. Code and derived results are available from the corresponding author upon reasonable request.

Funding

This work was supported without any funding.

Conflicts of Interest

The authors declare no conflicts of interest.

AI Use Statement

The authors declare that no generative AI was used in the preparation of this manuscript.

Ethical Approval and Consent to Participate

This study is a secondary analysis of de-identified data from publicly available databases (PTB-XL, OhioT1DM, MIMIC-III Waveform, and WESAD). Collection of these data was approved by the institutional review boards or ethics committees of the original studies, with informed consent obtained or waived as described in the respective data descriptors~\cite{wagner2020,marling2020,johnson2016,schmidt2018}. Access to MIMIC-III and OhioT1DM was obtained under their data use agreements. No new data were collected from human participants and no animal experiments were performed; therefore, no additional ethical approval was required.

References

  1. Joyia, G. J., Liaqat, R. M., Farooq, A., & Rehman, S. (2017). Internet of Medical Things (IoMT): Applications, benefits and future challenges in healthcare domain. Journal of Communications, 12(4), 240-247.
    [CrossRef] [Google Scholar]
  2. Farahani, B., Firouzi, F., Chang, V., Badaroglu, M., Constant, N., & Mankodiya, K. (2018). Towards fog-driven IoT eHealth: Promises and challenges of IoT in medicine and healthcare. Future Generation Computer Systems, 78, 659-676.
    [CrossRef] [Google Scholar]
  3. McCloskey, M., & Cohen, N. J. (1989). Catastrophic interference in connectionist networks: The sequential learning problem. Psychology of Learning and Motivation, 24, 109-165.
    [CrossRef] [Google Scholar]
  4. Goodfellow, I. J., Mirza, M., Xiao, D., Courville, A., & Bengio, Y. (2013). An empirical investigation of catastrophic forgetting in gradient-based neural networks. arXiv preprint arXiv:1312.6211.
    [CrossRef] [Google Scholar]
  5. Rolnick, D., Ahuja, A., Schwarz, J., Lillicrap, T. P., & Wayne, G. (2019). Experience replay for continual learning. In Advances in Neural Information Processing Systems (Vol. 32, pp. 350-360).
    [Google Scholar]
  6. Rao, D., Visin, F., Rusu, A. A., Teh, Y. W., Pascanu, R., & Hadsell, R. (2019). Continual unsupervised representation learning. In Advances in Neural Information Processing Systems (Vol. 32, pp. 7647-7657).
    [Google Scholar]
  7. Pellegrini, L., Graffieti, G., Lomonaco, V., & Maltoni, D. (2020). Latent replay for real-time continual learning. In 2020 IEEE/RSJ International Conference on Intelligent Robots and Systems (IROS) (pp. 10203-10209). IEEE.
    [CrossRef] [Google Scholar]
  8. Hayes, J., Melis, L., Danezis, G., & De Cristofaro, E. (2019). LOGAN: Membership inference attacks against generative models. Proceedings on Privacy Enhancing Technologies, 2019(1), 133-152.
    [CrossRef] [Google Scholar]
  9. Hu, H., Salcic, Z., Sun, L., Dobbie, G., Yu, P. S., & Zhang, X. (2022). Membership inference attacks on machine learning: A survey. ACM Computing Surveys, 54(11s), 1-37.
    [CrossRef] [Google Scholar]
  10. Dwork, C., McSherry, F., Nissim, K., & Smith, A. (2006). Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography Conference (pp. 265-284). Springer.
    [CrossRef] [Google Scholar]
  11. Kairouz, P., Oh, S., & Viswanath, P. (2017). The composition theorem for differential privacy. IEEE Transactions on Information Theory, 63(6), 4037-4049.
    [CrossRef] [Google Scholar]
  12. Dwork, C., & Roth, A. (2014). The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3-4), 211-407.
    [CrossRef] [Google Scholar]
  13. Lai, P., Hu, H., Phan, N., Jin, R., Thai, M. T., & Chen, A. (2022). Lifelong DP: Consistently bounded differential privacy in lifelong machine learning. In Proceedings of the 1st Conference on Lifelong Learning Agents (PMLR 199, pp. 778-797).
    [Google Scholar]
  14. Dwork, C., Rothblum, G. N., & Vadhan, S. (2010). Boosting and differential privacy. In 2010 IEEE 51st Annual Symposium on Foundations of Computer Science (pp. 51-60). IEEE.
    [CrossRef] [Google Scholar]
  15. Mironov, I. (2017). R\'enyi differential privacy. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF) (pp. 263-275). IEEE.
    [CrossRef] [Google Scholar]
  16. Bun, M., & Steinke, T. (2016). Concentrated differential privacy: Simplifications, extensions, and lower bounds. In Theory of Cryptography Conference (pp. 635-658). Springer.
    [CrossRef] [Google Scholar]
  17. Liu, C., Chakraborty, S., & Mittal, P. (2016). Dependence makes you vulnerable: Differential privacy under dependent tuples. In Network and Distributed System Security Symposium (NDSS). http://doi.org/10.14722/ndss.2016.23279
    [Google Scholar]
  18. Balle, B., Barthe, G., Gaboardi, M., & Geumlek, J. (2019). Privacy amplification by mixing and diffusion mechanisms. In Advances in Neural Information Processing Systems (Vol. 32, pp. 13277-13287).
    [Google Scholar]
  19. Wang, Y.-X., Balle, B., & Kasiviswanathan, S. P. (2019). Subsampled R\'enyi differential privacy and analytical moments accountant. In Proceedings of the 22nd International Conference on Artificial Intelligence and Statistics (PMLR 89, pp. 1226-1235). Extended version: Journal of Privacy and Confidentiality, 10(2), 2020.
    [CrossRef] [Google Scholar]
  20. Lopez-Paz, D., & Ranzato, M. (2017). Gradient episodic memory for continual learning. In Advances in Neural Information Processing Systems (Vol. 30, pp. 6467-6476).
    [Google Scholar]
  21. Alaa, A., van Breugel, B., Saveliev, E. S., & van der Schaar, M. (2022). How faithful is your synthetic data? Sample-level metrics for evaluating and auditing generative models. In Proceedings of the 39th International Conference on Machine Learning (PMLR 162, pp. 290-306).
    [Google Scholar]
  22. Torfi, A., Fox, E. A., & Reddy, C. K. (2022). Differentially private synthetic medical data generation using convolutional GANs. Information Sciences, 586, 485-500.
    [CrossRef] [Google Scholar]
  23. Abadi, M., Chu, A., Goodfellow, I., McMahan, H. B., Mironov, I., Talwar, K., & Zhang, L. (2016). Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (pp. 308-318). ACM.
    [CrossRef] [Google Scholar]
  24. Rogers, R. M., Roth, A., Ullman, J., & Vadhan, S. (2016). Privacy odometers and filters: Pay-as-you-go composition. In Advances in Neural Information Processing Systems (Vol. 29).
    [Google Scholar]
  25. Dinur, I., & Nissim, K. (2003). Revealing information while preserving privacy. In Proceedings of the 22nd ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems (pp. 202-210). ACM.
    [CrossRef] [Google Scholar]
  26. Kirkpatrick, J., Pascanu, R., Rabinowitz, N., Veness, J., Desjardins, G., Rusu, A. A., ... & Hadsell, R. (2017). Overcoming catastrophic forgetting in neural networks. Proceedings of the National Academy of Sciences, 114(13), 3521-3526.
    [CrossRef] [Google Scholar]
  27. Shin, H., Lee, J. K., Kim, J., & Kim, J. (2017). Continual learning with deep generative replay. In Advances in Neural Information Processing Systems (Vol. 30, pp. 2990-2999).
    [Google Scholar]
  28. De Lange, M., Aljundi, R., Masana, M., Parisot, S., Jia, X., Leonardis, A., ... & Tuytelaars, T. (2022). A continual learning survey: Defying forgetting in classification tasks. IEEE Transactions on Pattern Analysis and Machine Intelligence, 44(7), 3366-3385.
    [CrossRef] [Google Scholar]
  29. Farquhar, S., & Gal, Y. (2019). Differentially private continual learning. arXiv preprint arXiv:1902.06497.
    [CrossRef] [Google Scholar]
  30. Desai, P., Lai, P., Phan, N., & Thai, M. T. (2021, December). Continual learning with differential privacy. In International Conference on Neural Information Processing (pp. 334-343). Cham: Springer International Publishing.
    [CrossRef] [Google Scholar]
  31. Kaissis, G. A., Makowski, M. R., Rückert, D., & Braren, R. F. (2020). Secure, privacy-preserving and federated machine learning in medical imaging. Nature machine intelligence, 2(6), 305-311.
    [CrossRef] [Google Scholar]
  32. Yoon, J., Drumright, L. N., & Van Der Schaar, M. (2020). Anonymization through data synthesis using generative adversarial networks (ADS-GAN). IEEE journal of biomedical and health informatics, 24(8), 2378-2388.
    [CrossRef] [Google Scholar]
  33. Johnson, A. E., Pollard, T. J., Shen, L., Lehman, L. W. H., Feng, M., Ghassemi, M., ... & Mark, R. G. (2016). MIMIC-III, a freely accessible critical care database. Scientific data, 3(1), 160035.
    [CrossRef] [Google Scholar]
  34. Wang, L., Zhang, X., Su, H., & Zhu, J. (2024). A comprehensive survey of continual learning: Theory, method and application. IEEE Transactions on Pattern Analysis and Machine Intelligence, 46(8), 5362-5383.
    [CrossRef] [Google Scholar]
  35. Kairouz, P., McMahan, H. B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A. N., ... & Zhao, S. (2021). Advances and open problems in federated learning. Foundations and Trends in Machine Learning, 14(1-2), 1-210.
    [CrossRef] [Google Scholar]
  36. El Ouadrhiri, A., & Abdelhadi, A. (2022). Differential privacy for deep and federated learning: A survey. IEEE Access, 10, 22359-22380.
    [CrossRef] [Google Scholar]
  37. Wagner, P., Strodthoff, N., Bousseljot, R. D., Kreiseler, D., Lunze, F. I., Samek, W., & Schaeffter, T. (2020). PTB-XL, a large publicly available electrocardiography dataset. Scientific data, 7(1), 154.
    [CrossRef] [Google Scholar]
  38. Marling, C., & Bunescu, R. (2020, September). The OhioT1DM dataset for blood glucose level prediction: Update 2020. In CEUR workshop proceedings (Vol. 2675, p. 71). https://pmc.ncbi.nlm.nih.gov/articles/PMC7881904/
    [Google Scholar]
  39. Goldberger, A. L., Amaral, L. A., Glass, L., Hausdorff, J. M., Ivanov, P. C., Mark, R. G., ... & Stanley, H. E. (2000). PhysioBank, PhysioToolkit, and PhysioNet: components of a new research resource for complex physiologic signals. circulation, 101(23), e215-e220.
    [CrossRef] [Google Scholar]
  40. Schmidt, P., Reiss, A., Duerichen, R., Marberger, C., & Van Laerhoven, K. (2018). Introducing WESAD, a multimodal dataset for wearable stress and affect detection. In Proceedings of the 20th ACM International Conference on Multimodal Interaction (pp. 400-408). ACM.
    [CrossRef] [Google Scholar]
  41. Jagielski, M., Ullman, J., & Oprea, A. (2020). Auditing differentially private machine learning: How private is private sgd?. Advances in Neural Information Processing Systems, 33, 22205-22216.
    [Google Scholar]
  42. Azuma, K. (1967). Weighted sums of certain dependent random variables. Tohoku Mathematical Journal, Second Series, 19(3), 357-367.
    [CrossRef] [Google Scholar]

Cite This Article

APA Style
Yogi, M. K., & Mundru, Y. (2026). PRISM-DP: Privacy-Resilient Infinite-Sequence Memory via Martingale-Based Differential Privacy Composition for Continual Autoencoder Learning in Medical IoT. Biomedical Informatics and Smart Healthcare, 2(3), 136-151. https://doi.org/10.62762/BISH.2026.293480
Export Citation
RIS Format
Compatible with EndNote, Zotero, Mendeley, and other reference managers
TY  - JOUR
AU  - Yogi, Manas Kumar
AU  - Mundru, Yamuna
PY  - 2026
DA  - 2026/09/26
TI  - PRISM-DP: Privacy-Resilient Infinite-Sequence Memory via Martingale-Based Differential Privacy Composition for Continual Autoencoder Learning in Medical IoT
JO  - Biomedical Informatics and Smart Healthcare
T2  - Biomedical Informatics and Smart Healthcare
JF  - Biomedical Informatics and Smart Healthcare
VL  - 2
IS  - 3
SP  - 136
EP  - 151
DO  - 10.62762/BISH.2026.293480
UR  - https://www.icck.org/article/abs/BISH.2026.293480
KW  - continual learning
KW  - differential privacy
KW  - Medical IoT
KW  - autoencoder
KW  - martingale composition
KW  - unbounded task sequence
KW  - latent replay
KW  - R\'enyi DP
KW  - PTB-XL
KW  - OhioT1DM
AB  - Rehearsal-based continual learning in Medical IoT (MIoT) autoencoders requires replaying latent codes of past clinical tasks to prevent catastrophic forgetting. When these latent codes are derived from patient data, each replay constitutes a fresh privacy query, and existing differential privacy (DP) composition theorems-designed for finite, pre-specified query sequences-fail to bound cumulative privacy leakage over an unbounded task horizon. This paper presents PRISM-DP, a Privacy-Resilient Infinite-Sequence Memory framework that introduces a martingale-based DP composition theorem for unbounded replay sequences. PRISM-DP proves that a geometrically decaying per-task privacy schedule combined with a replay correlation decoupling lemma yields a convergent total privacy leakage bound for continual autoencoders. A privacy-amplified replay subsampling mechanism further tightens the per-replay leakage. Evaluated across 10 sequential clinical tasks on the PTB-XL, OhioT1DM, MIMIC-III Waveform, and WESAD datasets, PRISM-DP achieves an average AUC-ROC of 0.871, a backward transfer of $-0.055$, and keeps the total privacy budget within $\varepsilon=0.667$ at $\varepsilon_{\mathrm{cap}}=1.0$, outperforming all DP-certified baselines while providing a formally certified privacy guarantee for infinite-horizon continual MIoT learning.
SN  - 3068-5524
PB  - Institute of Central Computation and Knowledge
LA  - English
ER  - 
BibTeX Format
Compatible with LaTeX, BibTeX, and other reference managers
@article{Yogi2026PRISMDP,
  author = {Manas Kumar Yogi and Yamuna Mundru},
  title = {PRISM-DP: Privacy-Resilient Infinite-Sequence Memory via Martingale-Based Differential Privacy Composition for Continual Autoencoder Learning in Medical IoT},
  journal = {Biomedical Informatics and Smart Healthcare},
  year = {2026},
  volume = {2},
  number = {3},
  pages = {136-151},
  doi = {10.62762/BISH.2026.293480},
  url = {https://www.icck.org/article/abs/BISH.2026.293480},
  abstract = {Rehearsal-based continual learning in Medical IoT (MIoT) autoencoders requires replaying latent codes of past clinical tasks to prevent catastrophic forgetting. When these latent codes are derived from patient data, each replay constitutes a fresh privacy query, and existing differential privacy (DP) composition theorems-designed for finite, pre-specified query sequences-fail to bound cumulative privacy leakage over an unbounded task horizon. This paper presents PRISM-DP, a Privacy-Resilient Infinite-Sequence Memory framework that introduces a martingale-based DP composition theorem for unbounded replay sequences. PRISM-DP proves that a geometrically decaying per-task privacy schedule combined with a replay correlation decoupling lemma yields a convergent total privacy leakage bound for continual autoencoders. A privacy-amplified replay subsampling mechanism further tightens the per-replay leakage. Evaluated across 10 sequential clinical tasks on the PTB-XL, OhioT1DM, MIMIC-III Waveform, and WESAD datasets, PRISM-DP achieves an average AUC-ROC of 0.871, a backward transfer of \$-0.055\$, and keeps the total privacy budget within \$\varepsilon=0.667\$ at \$\varepsilon\_{\mathrm{cap}}=1.0\$, outperforming all DP-certified baselines while providing a formally certified privacy guarantee for infinite-horizon continual MIoT learning.},
  keywords = {continual learning, differential privacy, Medical IoT, autoencoder, martingale composition, unbounded task sequence, latent replay, R\'enyi DP, PTB-XL, OhioT1DM},
  issn = {3068-5524},
  publisher = {Institute of Central Computation and Knowledge}
}

Article Metrics

Citations
Crossref
0
Scopus
0
Views
21
PDF Downloads
3

Publisher's Note

ICCK stays neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and Permissions

CC BY Copyright © 2026 by the Author(s). Published by Institute of Central Computation and Knowledge. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/), which permits use, sharing, adaptation, distribution and reproduction in any medium or format, as long as you give appropriate credit to the original author(s) and the source, provide a link to the Creative Commons licence, and indicate if changes were made.
Biomedical Informatics and Smart Healthcare
Biomedical Informatics and Smart Healthcare
ISSN: 3068-5524 (Online)
Portico
Preserved at
Portico