Skip to content
#small language model Open access

Balancing privacy and performance: the impact of facial defacing on AI in medical imaging.

Aug 2026 · EBioMedicine · Vol 131, pp. 106457 · 0 citations · 37 references
Medicine

Abstract

Background

Recent NIH Data Management and Sharing (DMS) policy updates and NIH controlled-access data security requirements have increased attention to facial anonymization and controlled-access handling of shared head imaging data. This is particularly relevant for datasets submitted to or hosted by the Cancer Imaging Archive (TCIA), where NCI Cancer Imaging Program/TCIA implementation practices address imaging data containing potentially reconstructable facial anatomy. While intended to protect patient privacy and strengthen public trust, defacing can distort craniofacial geometry and alter image statistics, potentially compromising the fidelity and reproducibility of artificial intelligence (AI) models trained on such data. Existing studies primarily validate visual anonymization quality, but few have quantified its downstream impact on deep learning-based medical imaging tasks. Understanding this privacy-utility trade-off is crucial for responsible data sharing and compliant AI development.

Methods

We systematically evaluated three representative defacing algorithms, two invasive (QuickShear and Py-Deface) and one less destructive, facial replacement (mri_reface), across MRI and CT datasets from 600 subjects spanning three institutions. Model performance was assessed on three clinically relevant applications: (1) brain segmentation and Evans ratio biomarker quantification in normal pressure hydrocephalus (NPH) MRI using SLANT and FreeSurfer; (2) representative-slice selection and diagnostic reasoning for brain tumour MRI using vision-language models (VLMs); and (3) automated emergency head CT report generation using a fine-tuned Otter-based vision-language model. Each method's impact was quantified using Dice similarity, correlation metrics, reasoning accuracy, and natural-language generation scores (BLEU, METEOR, ROUGE, CIDEr).

Findings

Invasive algorithms caused significant degradation across all tasks. QuickShear reduced mean Dice scores by up to 9% and introduced 14-19% failure rates during quality control, while PyDeface induced smaller but measurable performance losses. mri_reface maintained 100% success without any failures and achieved segmentation, diagnostic, and report-generation accuracy within 3-5% of the original data. Evans ratio distributions remained statistically consistent between mri_reface and original images (p > 0.05), whereas invasive methods introduced broader variance. Across all VLM tasks, mri_reface preserved high correlation with radiologist-selected slices (r = 0.979) and stable report-generation quality (BLEU-4 = 0.11 ± 0.06 vs. 0.12 ± 0.07 for original).

Interpretation

Facial anonymization introduces a measurable privacy-utility trade-off that must be explicitly considered in the design of AI-ready medical imaging datasets. Invasive defacing compromises geometric and statistical integrity, reducing downstream model accuracy even outside facial regions. Facial replacement anonymization methods, such as mri_reface, effectively reconcile patient privacy with reproducibility, offering a practical path to NIH-compliant open data. Future regulatory and institutional policies should integrate quantitative privacy-utility assessment and mandate transparent reporting of anonymization pipelines to ensure that shared imaging data remain both ethically safe and scientifically valid under emerging digital health frameworks.

Funding

This work was partially supported by the American Heart Association (Award No. 25IPA1454088), the National Institutes of Health (Award No. 1R03CA286693-01A1 and Award No. 1R01CA291826-01A1), the U.S. Department of Defense (Award No. HT94252510807), and the National Science Foundation (Award No. 2545071).

Read PDF

Similar papers

Conference Jul 2026

Unmasking the algorithm: a review of algorithmic bias and fairness in medical AI and image processing

The integration of Generative Artificial Intelligence (AI) into medical image processing has substantial potential for transforming diagnostic workflows, accelerating image reconstruction, and improving clinical decision-making. However, this technological shift brings significant ethical challenges, particularly concerning algorithmic bias and fairness. This paper reviews the ethical issues surrounding AI-generated content in medical imaging, focusing on how biases are introduced and amplified, and how they impact patient care across diverse demographic groups. We categorize the taxonomy of ethical concerns—including algorithmic fairness, privacy, transparency, and clinical accountability—and trace the workflow of bias from unrepresentative training datasets through flawed objective functions to biased clinical deployment. By analyzing the vulnerabilities of generative models, such as Generative Adversarial Networks (GANs) and diffusion models, we examine the phenomenon of underdiagnosis bias and the magnification of historical disparities. We also discuss mitigation strategies, including data-centric approaches to ensure representative sampling and model-centric techniques such as adversarial debiasing. Ensuring fairness and equity in medical AI is necessary for its safe and effective clinical adoption.

G. Shi, Hailian Zhang, Chun Xie et al. · 0 citations
Open access Aug 2026

Local Deployment of Open-Weight Language Models in Dermatology: Viewpoint on Privacy, Equity, and Practical Implementation

Abstract Generative AI, particularly large language models (LLMs), is reshaping clinical workflows in dermatology. However, cloud-based commercial models pose persistent challenges to Health Insurance Portability and Accountability Act (HIPAA) compliance, especially in dermatology, where protected health information (PHI) extends beyond text to clinical photographs, dermoscopic images, and total-body photography that may capture identifiable anatomical features and document conditions carrying social stigma. Locally hosted, open-weight LLMs that are run within the institution’s own infrastructure offer dermatology practices a pathway to leverage AI capabilities while retaining full control of their data. This viewpoint synthesizes evidence on when locally hosted, open-weight LLMs should be preferred for dermatologic workflows, when cloud deployment may remain preferable, and how multimodal AI fits into a coherent local deployment strategy. We advance 4 arguments. First, model compression techniques (knowledge distillation, structured pruning, and low-bit quantization) together with mixture-of-experts architectures have lowered hardware thresholds enough that 7- to 33-billion-parameter models now run on consumer-grade workstations with modest neural processing units or graphics processing units. Second, dermatology is fundamentally a visual specialty, and a credible local deployment strategy must integrate LLMs with vision models, including convolutional neural networks, vision transformers, vision-language models, and dermatology-specific foundation models such as PanDerm and medical multimodal models such as MedGemma. Third, locally hosted, open-weight models confer specific advantages for dermatology, including complete institutional control of clinical images, freedom from vendor model deprecation that disrupts validated workflows, and the ability to audit and fine-tune models to address well-documented performance gaps in skin of color. Fourth, local deployment is not a panacea; cloud models remain preferable for some tasks, and local deployment introduces governance challenges (heterogeneity across practices, model drift, and quantization-induced accuracy loss) that require structured mitigation through validated reporting frameworks such as CONSORT-AI (Consolidated Standards of Reporting Trials), SPIRIT-AI (Standard Protocol Items: Recommendations for Interventional Trials), DECIDE-AI (Developmental and Exploratory Clinical Investigations of Decision support systems driven by AI), and TRIPOD+AI (Transparent Reporting of a Multivariable Prediction Model for Individual Prognosis or Diagnosis), as well as retrieval-augmented generation and federated learning approaches. We situate these arguments within the international regulatory landscape, including the European Union’s General Data Protection Regulation, the European Union AI Act, and Germany’s Digitale Gesundheitsanwendungen (DiGA) framework, in addition to HIPAA. We provide quantitative cost examples showing that current consumer hardware capable of running 14- to 33-billion-parameter models can be acquired for roughly the price of 1 to 2 years of enterprise cloud-AI subscriptions. We close by mapping a practical implementation pathway and identifying near-term research priorities. Locally hosted, open-weight LLMs that are deployed thoughtfully and within governance frameworks offer dermatology practices a credible route to harness generative AI while preserving regulatory compliance, equity across skin types, and the dermatologist-patient relationship.

William J. Nahm, Emily S Yin, Emily C. Milam et al. · 0 citations
Preprint Jul 2026

Secure-by-Disguise: A Systematic Evaluation of Image Disguising for Confidential Medical Image Modeling

Cloud-based deep learning enables large-scale medical image analysis but raises significant privacy concerns when sensitive patient images are outsourced for model development. Image disguising has recently emerged as a promising privacy-enhancing technology (PET) that transforms images into visually unintelligible representations while preserving information for downstream learning. We established a unified framework to evaluate representative methods, DisguisedNets and NeuraCrypt, across four datasets involving classification and semantic segmentation tasks. Our analysis assessed predictive utility, efficiency, and robustness against reconstruction attacks. Results showed that image disguising performance varies significantly between tasks; while methods preserved utility for medical image classification, they caused substantial degradation in dense semantic segmentation. Specifically, Randomized Multidimensional Transformation (RMT) offered the optimal balance of performance and security, whereas AES-based disguising severely impacted utility. Furthermore, regression-based reconstruction attacks effective on natural images proved considerably less successful on realistic medical images. These findings provide a systematic assessment of PET suitability for confidential medical AI applications.

Jason Rojas, Jiajie He, Yash J. Patel et al. · 0 citations
#generative ai Preprint Aug 2026

Masking Is Not Enough: Generative Restoration for Multimodal De-Identification in Medical AI

ClinX is introduced, an end-to-end multimodal PHI sanitization framework for medical image-text data, and results show that OCR-only masking is not sufficient as a standalone solution, and restoration-based sanitization better preserves clinically relevant visual context while sharply reducing recoverable PHI.

S. Shrestha, Zongxing Xie, Chen Zhao et al. · 0 citations
Open access Jul 2026

Machine Learning-Based Privacy Preserving via CT/MRI and Organ Metadata Prediction.

Medical imaging plays a significant role in diagnosis and treatment planning, with significant efforts focused on training machine learning (ML) algorithms to perform detection and classification automatically. However, concerns regarding patient privacy have prompted the need for robust deidentification of the data. In this paper, we consider a general scenario in which the data are entirely anonymized by removing the metadata due to privacy concerns. In several circumstances, efficient training of an arbitrary downstream ML model requires some prior information that is only accessible through metadata. To address this need, we propose a novel approach for automated metadata prediction from fully anonymized CT and MRI images to enable efficient training of the downstream model. Our method accurately identifies the imaging modality (CT or MRI) and anatomical region (heart, brain, or liver) directly from image data. Moreover, in case of MRI data, it allows for contrast classification into T1 and T2. Our framework employs a set of machine learning as well as deterministic techniques to perform these tasks, achieving high accuracy rates in distinguishing between CT and MRI scans and localizing anatomical regions, as well as classification of MRI imaging protocol, T1 and T2. By estimating technical metadata from anonymized data, our approach successfully combines multiple tasks into a unified framework designed for privacy-preserving workflows. We demonstrate the effectiveness and practicality of our method through systematic experiments on medical imaging datasets. On held-out test sets, the framework achieved 100% accuracy for CT/MRI modality detection; 99.2% accuracy for anatomical region classification across brain, heart, and liver volumes (125/126 correctly classified); and 99.8% accuracy for MRI T1/T2 protocol classification (500/501 correctly classified). The proposed framework represents a new direction toward full privacy protection in medical imaging with no impact on the selection of appropriate image processing frameworks in the downstream tasks.

Riwei Jin, S. Mohamadi, Matthew T. Bramlet et al. · 0 citations

Related blog posts