acceptodds
Under review as a conference paper at ICLR 2027

Foreground-Matched Occlusion Controls for Auditing Annotated-Region Sensitivity in Medical VLMs

Abstract

Occlusion audits of medical vision-language models (VLMs) read a larger answer shift from blacking out an annotated region than from a same-sized control box as use of the region, assuming both occlusions are equally strong. A black fill on air changes almost no pixels, so a control there loses to nearly any tissue occlusion. A minimum-overlap control could favour air (replayed on 229 items, its mean tissue coverage was 0.659 against 0.943 matched), and under it every model run appeared region-sensitive. We introduce a foreground-matched control (same size, matched tissue coverage, no overlap with any annotated box) and a proposition showing, under a monotone foreground-dose model, that a comparator covering less tissue biases the win rate upward and matching bounds that term. On SLAKE the matched control gives graded sensitivity: both MedGemma checkpoints lead (strict-win rates 0.639 and 0.612) and survive post-hoc resampling of 175 source images, while four general models are lower (0.525–0.563) and their detection mostly depends on how ties are scored. The scope is as follows: historical and matched runs are unpaired except for MedGemma-4B, whose CIPE win rate is marginally lower when matched, so we do not attribute their difference to the control; 93.0% of the 229 items sit on images the MedGemma family reports training on, so the ranking is exposure-confounded and is not read as specialisation; and our CIPE readout showed no advantage over cheaper ones in a pre-registered head-to-head. The masked boxes annotate the image, not the question target, so this is image-level sensitivity, not target localisation, for one specialist family at two scales on the 229 of 400 SLAKE items admitting a matched control, which favour sparsely annotated images. We also build MedTrust-IN v0.3 (released upon publication): 1,122 panel-defined text-only-hard medical-VQA items from source test splits, with a fail-closed build-time provenance gate. An audit should report and match what its control covers, drop and count unmatched items, and report ties at half credit beside strict wins.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.