Threshold-Sensitive Subgroup Privacy Gaps in Medical Foundation-Model Adaptation
Abstract
Subgroup membership-inference gaps can reflect unequal privacy exposure, shared-threshold artifacts, or split confounding. We examine these explanations in frozen-encoder medical foundation-model adaptation using seven retinal membership seeds, a limited chest X-ray comparator, subgroup-specific thresholds, a metadata-only split control, and a planted-feature canary. Under one global threshold, retinal race gaps recur, especially for ImageNet-ViT-L; under subgroup-specific thresholds, both encoders’ mean gaps fall below the exploratory .03 threshold. A large metadata-only gap prevents attributing the observed disparity to model-induced leakage. The easy canary is detected at strengths α≥0.5 across three seeds, showing sensitivity to that intervention but not power for natural leakage. We therefore recommend reporting both global- and subgroup-threshold results, split controls, recurrence, and implementation canaries. Because only aggregate evidence survives, this is a retrospective work-in-progress rather than a replayable benchmark.