\section{Discussion}\label{sec:discussion}

While deep learning presents great promise for solving neuroimaging problems, it also brings new challenges. Deep learning is intrinsically data-hungry, but the bulk of neuroimaging data is distributed around the world in private repositories. With classic machine learning approaches like linear regression, model sharing and meta-analysis could be used to pool insights without sharing data. Unfortunately, neural networks are capable of completely memorizing training data, so that sharing a model may be just as bad as sharing the private data itself. In this paper, we demonstrated a practical proof-of-concept attack for extracting private information from neural networks trained on neuroimaging data.  
We showed that attacks with a high success rate persist under various settings, including a realistic, distributed, federated learning scheme explicitly designed to protect private information. 
Although concerning, our preliminary study of attacks and defenses suggest benefits to solving this problem that go beyond data privacy. 
Because attacks exploit differences in model performance on training data and unseen test data, a successful defense must also lead to more robust neuroimaging models whose out-of-sample performance does not significantly differ from in-sample performance. Hence, even if data privacy were not a concern, further study of protection against membership attacks may inspire neuroimaging models that generalize better to new patients. 
