According to arxiv.org, researchers have introduced PrivMeSA, a privacy-aware self-evolving multi-agent system designed to protect patient information while consulting more capable remote AI models in clinical settings.
The system addresses a critical vulnerability: while local clinical LLM agents can consult remote models for expertise, such consultations risk exposing patient data. According to the research, “quasi-identifiers can accumulate across multi-turn consultations and repeated patient visits to enable re-identification,” even when explicit identifiers are removed.
PrivMeSA employs reinforcement learning to balance task accuracy against disclosure and re-identification risk, with privacy evaluated over complete outbound transcripts. The system includes a “lesson memory” that distills completed consultations into generalized clinical guidance, allowing subsequent cases to reuse expertise without repeated remote exchanges. According to arxiv.org, this memory “grows without additional outcome labels or parameter updates.”
In testing on an emergency-department benchmark built from MIMIC-IV-ED records, arxiv.org reports that PrivMeSA improved mean task accuracy by up to 15.8 percentage points over standard delegation approaches. The system reduced disclosure of personal details from 98.0% to 0.2% of cases and decreased the share of cases where patients could be narrowed to ten or fewer registry patients from 74% to 0%.
The research was published October 1, 2026, on arxiv.org.