Foreground-Matched Occlusion Controls for Auditing Annotated-Region Sensitivity in Medical VLMs
Abstract
Occlusion audits of medical vision-language models (VLMs) read a larger answer shift from blacking out an annotated region than from a same-sized control box as use of the region, assuming both occlusions are equally strong. A black fill on air changes almost no pixels, so a control there loses to nearly any tissue occlusion. A minimum-overlap control could favour air (replayed on 229 items, its mean tissue coverage was 0.659 against 0.943 matched), and under it every model run appeared region-sensitive. We introduce a foreground-matched control (same size, matched tissue coverage, no overlap with any annotated box) and a proposition showing, under a monotone foreground-dose model, that a comparator covering less tissue biases the win rate upward and matching bounds that term. On SLAKE the matched control gives graded sensitivity: both MedGemma checkpoints lead (strict-win rates 0.639 and 0.612) and survive post-hoc resampling of 175 source images, while four general models are lower (0.525–0.563) and their detection mostly depends on how ties are scored. The scope is as follows: historical and matched runs are unpaired except for MedGemma-4B, whose CIPE win rate is marginally lower when matched, so we do not attribute their difference to the control; 93.0% of the 229 items sit on images the MedGemma family reports training on, so the ranking is exposure-confounded and is not read as specialisation; and our CIPE readout showed no advantage over cheaper ones in a pre-registered head-to-head. The masked boxes annotate the image, not the question target, so this is image-level sensitivity, not target localisation, for one specialist family at two scales on the 229 of 400 SLAKE items admitting a matched control, which favour sparsely annotated images. We also build MedTrust-IN v0.3 (released upon publication): 1,122 panel-defined text-only-hard medical-VQA items from source test splits, with a fail-closed build-time provenance gate. An audit should report and match what its control covers, drop and count unmatched items, and report ties at half credit beside strict wins.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.