A healthcare organization uses an AI model to predict patient readmission risk. To comply with patient privacy regulations, they apply differential privacy during training. What is the primary trade-off of using differential privacy?
Differential privacy injects calibrated noise into training data or gradients, mathematically bounding any individual's influence on the model. This privacy guarantee inherently perturbs learned parameters, degrading predictive performance. The trade-off is therefore measurable accuracy loss, which the healthcare scenario accepts to satisfy patient privacy regulations.
Why this answer
Differential privacy works by adding calibrated noise to the training process or model outputs, which directly reduces the model's accuracy in exchange for a quantifiable privacy guarantee (e.g., ε-differential privacy). This trade-off is fundamental: stronger privacy (lower ε) requires more noise, which degrades predictive performance. The healthcare organization must balance the need to protect patient data against the clinical utility of accurate readmission predictions.
Exam trap
The AI0-001 exam often tests the misconception that differential privacy primarily reduces bias or improves fairness, when in fact its core trade-off is accuracy for privacy, and fairness can be negatively impacted by the added noise.
How to eliminate wrong answers
Option A is wrong because differential privacy does not primarily target bias reduction; it addresses privacy, and increased training time is a secondary implementation cost, not the primary trade-off. Option B is wrong because differential privacy does not inherently lower interpretability or increase fairness; it may even reduce fairness if noise disproportionately affects minority subgroups, and interpretability is a separate concern. Option C is wrong because differential privacy does not improve inference speed or reduce memory usage; it typically adds computational overhead during training and does not affect inference latency or memory footprint.