Quantifying Privacy Risks in Foundation Model Representations of Brain MRI
Abstract
Foundation models' utility and generalization capabilities are widely studied; however, their privacy implications remain understudied. We evaluate the re-identification risk of five foundation models embeddings spanning different learning paradigms, backbones, and training data, applied to two T1-weighted brain MRI datasets, OASIS-2 and MIRIAD. Using a threat model in which an attacker holds only the leaked embeddings, the same open-source foundation model, and an auxiliary MRI dataset, we quantify risk with re-identification rate, Equal Error Rate, and linkability. We find that all five models leak identity related information, with re-identification rates reaching up to 99\% on MIRIAD and exceeding 90\% on OASIS-2 for the riskiest model, even though none were trained with an identification objective. Models trained specifically on brain MRI data pose the highest risk, while a task-specific segmentation model is comparatively safer, though still far from private. We further show that these embeddings also leak demographic attributes such as sex. Our results demonstrate that foundation model embeddings are not safe, leak privacy, and are unsuitable as an anonymization mechanism as embeddings should not be presumed privacy-preserving merely because raw images are withheld.