{"id":"748ed784-6303-4b5b-9993-985d14e35eff","arxiv_id":"2603.02288","paper_version":2,"verdict":"CONDITIONAL","confidence":"MODERATE","novelty_score":6.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":6,"one_line_summary":"AutoFFS uses adversarial deformations of skull scans, guided by an ensemble of sex classifiers, to generate counterfactual male/female skull morphologies for surgical planning.","lead":"AutoFFS is a machine-learning method that reshapes 3D skull models toward the opposite sex's typical bone shape by nudging them until sex-classification AI labels them as that sex. It aims to give facial feminization surgeons a quantitative, patient-specific preview of possible skull changes before surgery.","discovery_kind":"new_application","skeptic_critique":{"model":"deepseek-v4-flash","headline":"The deformation target and the main success metrics derive from classifiers trained on the same single-cohort MR dataset, so the claim of clinically meaningful feminization lacks independent anatomical ground truth.","rationale":"The reader's weakest assumption correctly identifies the reliance on SMSC-trained classifiers as the normative guide for feminization. My stress-test extends this: even if those classifiers capture some true dimorphism, the paper's evaluation loop is closed because the optimization target, the flip-rate metric, and the distributional metrics all derive from classifiers trained on the same cohort. The human perceptual study is genuinely independent evidence, but it tests perceived sex, not anatomical validity or surgical feasibility. This is not an internal inconsistency—the method is coherent and the qualitative deformations align with known dimorphic regions—but the external validity of the central claim is under-supported. The paper's own acknowledgment that no paired ground-truth data exist is the key missing link. The recommended verdict remains CONDITIONAL: the method is a plausible proof-of-concept, but the clinical-planning claim requires external validation against actual post-operative anatomy or an independent CT cohort.","tokens_in":10666,"tokens_out":5912,"duration_ms":63215,"concrete_test":"Obtain 10–15 pre- and post-operative CT skulls from FFS patients; run AutoFFS with the published SMSC-trained ensemble on each pre-op CT, then rigidly align the generated feminized skull to the actual post-op skull and compare surface distance and direct cephalometric deltas (brow projection, bigonial width, chin height) against an identity baseline. If generated differences are no closer than identity or disagree in sign, the classifier-flip is not surgical feminization. If post-op data are unavailable, substitute an independent CT-trained sex classifier: require the pretrained deformation to flip that classifier and move direct measurements toward female norms.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The most load-bearing assumption is not just that the SMSC-trained classifiers capture true skeletal sexual dimorphism; it is that optimizing a deformation to flip those classifiers is equivalent to feminization. That equivalence is unvalidated. The optimization objective (Algorithm 1) and the headline classifier evaluation are both defined by classifiers trained on the same 444-scan MS cohort; the 'hold-out' evaluators are different architectures trained on the same split and cohort. Adversarial examples transfer across such architectures, so the 100% flip rate is not independent evidence. MFD/MKD are computed from a hold-out classifier's embedding space trained on the same cohort, so they inherit the same possible cohort/scanner bias. The paper itself states in §3.1 that no paired ground-truth or post-operative data exist and explicitly declines post-op comparison. The only independent signal is the perceptual study (N=11), which tests perceived sex rather than anatomical correctness; the drop to 37% accuracy shows a perceptual shift, but not that the deformation matches actual female skull morphology or a feasible FFS plan. Thus the central claim—that these counterfactual morphologies provide a quantitative foundation for FFS planning—rests on an unverified equivalence between classifier fooling and surgical feminization.","agreement_with_reader":"partial"},"referee_report":{"model":"deepseek-v4-flash","summary":"The paper proposes AutoFFS, a framework that generates counterfactual skull morphologies for facial feminization/masculinization surgery planning. The method performs a targeted adversarial attack: a regularized B-spline free-form deformation is optimized to flip an ensemble of pre-trained binary sex classifiers from the source sex to the target sex, thereby producing a deformed skull that the classifiers assign to the target class. Evaluation uses hold-out classifier flip rates, two proposed distributional metrics (MFD and MKD) computed in a hold-out classifier's embedding space, a qualitative comparison with anthropological dimorphism descriptions, and a human perceptual study. The central claim is that the resulting counterfactual morphologies provide a quantitative, data-driven foundation for preoperative FFS planning.","tokens_in":11017,"tokens_out":3232,"duration_ms":34894,"significance":"If the central claim were validated, this would be a meaningful contribution to an underserved clinical area. The technical framing—repurposing adversarial attacks as anatomically regularized shape editing—is clever, and the ensemble-plus-FFD pipeline is clearly described. The paper also ships an open project page and proposes new evaluation metrics (MFD/MKD) that could be reused. However, the clinical significance depends entirely on an equivalence that the paper does not establish: that a deformation which flips a sex classifier trained on a single MR cohort is equivalent to feminization as understood by craniofacial surgeons. The current evidence is largely circular or subjective, so the contribution is best viewed as a proof-of-concept in need of external anatomical and clinical validation.","major_comments":[{"comment":"The headline 100% flip rate is effectively the optimization objective reproduced on a different architecture. The hold-out classifiers are trained on the same 444-scan SMSC cohort and same train/test split as the optimization classifiers; adversarial examples are known to transfer across architectures trained on the same data. Consequently, the flip rate demonstrates that the attack transfers, not that the deformation represents a clinically valid female morphology. To support the central claim, the deformations should be compared against independent anatomical ground truth, e.g., quantitative sex-dimorphism measurements from a separate CT dataset or expert craniofacial assessment of whether the induced changes match FFS targets.","section":"§3.1, Classifier-Based Evaluation, Fig. 3"},{"comment":"MFD and MKD are computed in the penultimate-layer feature space of a hold-out classifier trained on the same SMSC cohort. Any cohort-specific or scanner-specific bias in that classifier is inherited by these metrics, so they do not constitute an independent test of morphological alignment. Moreover, the intra-class noise floor is MFD≈0.2–0.6, while the generated-to-real MFD is ≈10–11 after reduction from ≈57. The 82–86% reduction is relative to a very large inter-sex baseline; the generated distribution remains an order of magnitude farther from the real target than two random halves of the same real population. Reporting absolute distances and, ideally, metrics on independent landmark or surface measurements would give a more honest picture.","section":"§3.1, Distributional Alignment, Eqs. (8)–(9)"},{"comment":"The perceptual study (N=11) shows a statistically suggestive drop in perceived-male accuracy for generated skulls (37%), but this only tests whether raters perceive the target sex; it does not establish anatomical correctness, surgical feasibility, or consistency with actual female skull morphology. The low intra-rater agreement for generated skulls (κ_intra=0.43) indicates the morphologies are ambiguous even to the raters. The claim that these morphologies provide a 'quantitative foundation for preoperative planning' needs additional evidence, such as a structured evaluation by FFS surgeons on the plausibility and operability of the proposed bone changes, rather than only a sex-perception task on renders.","section":"§3.1, Human Perceptual Evaluation, Table 3"},{"comment":"The paper explicitly states that no paired ground-truth or post-operative data exist and declines post-operative comparison. This is the core load-bearing gap. Given that the optimization target and the main evaluation metrics are all derived from classifiers trained on the same single-cohort MR dataset, the current evidence cannot distinguish a genuinely feminizing deformation from a dataset-specific artifact. The paper should either temper the central claim to 'classifier-consistent counterfactuals' or add an external validation loop—for example, testing on an independent CT dataset, comparing the deformation field to published quantitative FFS planning norms, or having surgeons rate whether the deformation matches a feasible operative plan.","section":"§4, Limitations"}],"minor_comments":[{"comment":"Typos and formatting: 'we proposeAutoFFS' and 'sexandgender' lack spaces; 'Morphological Fréchet Distance' appears without consistent spacing in the abstract; Figure 2 labels 'Classiﬁer 1Classiﬁer 2...' run together without separators.","section":"Abstract, §2, §3"},{"comment":"The term 'hold-out classifiers' is slightly misleading: the two evaluation classifiers are trained on the same dataset split as the optimization classifiers, just with different architectures. Please clarify that they are architecture-hold-out, not data-hold-out.","section":"§3.1, Implementation Details"},{"comment":"Hyperparameters (λ_smooth, λ_bend, γ, τ, lattice) were selected based on qualitative assessment of anatomical plausibility. A sensitivity analysis, or at least a statement of how much the qualitative pattern depends on these values, would strengthen the reproducibility.","section":"§3.1, Footnote 4"},{"comment":"The dataset is an MS patient cohort from Switzerland; the paper notes this limitation but could also state explicitly that the classifiers therefore learn dimorphism as present in this specific population, and that transfer to other populations is unknown without additional data.","section":"§3, Dataset"}],"recommendation":"major_revision","confidential_remarks":"The stress-test concern is real and lands: the paper's central evaluation loop is largely self-referential. The idea is promising and the technical execution appears sound, but the clinical claim requires external validation that is currently absent. I would like to see at least one independent validation axis (CT data, quantitative anthropometric comparison, or expert surgeon assessment) before accepting the paper as a clinical-planning foundation. As a methods paper for counterfactual shape editing, it is a solid contribution; as a surgical planning tool, it is currently unsubstantiated."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"The core idea here is genuinely new: treat a free-form deformation as a targeted adversarial attack on an ensemble of sex classifiers to generate counterfactual skull morphologies for FFS planning. That framing is neat, the implementation is clean, and the qualitative results match known sexual dimorphism in the brow, chin, and zygomatic regions without any anatomical priors. The authors are also honest in the limitations section—they acknowledge the small single-cohort dataset, the use of MR-derived bone instead of CT, and the lack of paired ground truth. That honesty earns credit.\n\nBut the load-bearing problem is the evaluation. The classifier flip rate is literally the loss being optimized. Achieving 100% flip rate against hold-out architectures trained on the same cohort is roughly what you'd expect from adversarial transfer, not evidence of true feminization. The MFD/MKD metrics are computed in a feature space learned from the same single-cohort MR data, so they inherit whatever bias the classifiers learned. The paper itself says in §3.1 that no paired ground truth exists and explicitly declines post-op comparison. That leaves the human perceptual study (N=11) as the only independent signal—and it shows a perceptual shift, but not that the deformations match real female skull morphology or are surgically feasible. The claim that these counterfactuals provide a \"quantitative foundation\" for FFS planning is therefore stronger than the evidence supports.\n\nThat said, I don't think this is a desk-reject. It's a serious technical contribution with a clinically meaningful application. The adversarial-FFD combination is worth publishing if the claims are scaled back and the validation is improved. Concretely, the authors need independent anatomical ground truth—post-op CT when available, or at least landmark-based comparisons against known dimorphic measurements—and they should report the classifier-based results as attack success, not as evidence of clinical validity. The perceptual study also needs proper statistical handling and a larger rater pool. The code and data should be released so others can test whether the deformations transfer across datasets.\n\nWho is this for? Anyone working on data-driven surgical planning, counterfactual shape editing, or adversarial attacks in medical imaging. It's a serious paper with a clear soft spot. I'd send it to peer review with a request for major revision focused on independent validation. It deserves referee time, but the authors need to prove the equivalence between classifier fooling and feminization rather than asserting it.","headline":"A clever, well-engineered application of adversarial deformations to FFS planning, but the central validation is circular: the main metric is the optimization objective, and the only independent signal (a small human study) shows perceptual shift, not anatomical correctness.","tokens_in":11440,"tokens_out":1041,"would_cite":false,"duration_ms":11778,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"A targeted adversarial attack on sex classifiers yields counterfactual skull morphologies that could ground facial feminization surgery planning in quantitative anatomy.","keywords":["facial feminization surgery","counterfactual shape editing","adversarial deformations","free-form deformation","sex classification","skull morphology","surgical planning","ensemble adversarial attack"],"falsifier":"Train the same pipeline on a multi-center CT dataset with broad ethnic, age, and sex diversity, and apply it to male and female CT skulls. If the generated feminized skulls no longer flip hold-out CT-trained classifiers at high rates, or if the deformation hotspots move away from the brow, chin, and zygomatic regions that the paper identifies, the 'feminization direction' learned from the MR cohort is a dataset artifact rather than a general skeletal dimorphism.","tokens_in":10592,"feed_emoji":"💀","tokens_out":5374,"duration_ms":46787,"temperature":0.7,"pith_summary":"AutoFFS claims that a targeted adversarial attack on an ensemble of binary sex classifiers can serve as a clinically meaningful shape-editing tool: by optimizing a regularized free-form deformation of a skull until the classifiers confidently assign the opposite sex, the method produces a counterfactual skull morphology — the skull 'as if' it belonged to the target sex. The paper argues this provides a quantitative basis for preoperative planning in facial feminization surgery, which currently relies heavily on subjective clinical judgment. Three lines of evidence support the claim: hold-out classifiers flip on 100% of transformed test samples, two new population-level distributional metrics (MFD and MKD) show the generated populations align with their real target populations, and a human perceptual study found raters perceived the intended target sex in 63% of generated skulls. The deformations concentrate in brow, chin, and zygomatic regions, matching anthropological accounts of sexual dimorphism, despite no anatomical priors being imposed.","feed_headline":"Adversarial skull deformations plan facial feminization surgery","feed_subtitle":"Skull deformations that fool sex classifiers yield data-driven surgery blueprints.","key_machinery":"Free-form deformation (FFD): a 3D cubic B-spline control lattice that parameterizes a smooth displacement field applied to the skull image. At test time, the control-point offsets are optimized with respect to a loss that combines a smooth worst-case margin over an ensemble of sex classifiers (the targeted adversarial attack) with Jacobian-smoothness and bending-energy regularizers. The deformation field is applied to the input skull X via resampling, X' = X ∘ Φ, and the whole pipeline is differentiable end-to-end through the classifier gradients. The central object is the optimized deformation field itself — it is the counterfactual morphology.","core_discovery":"The central discovery is that the gradient from a targeted adversarial attack on a pre-trained sex classifier ensemble, when channeled through a B-spline free-form deformation and regularized for smoothness and bending energy, identifies a meaningful direction in skull morphology space: the direction that shifts a skull across the learned boundary between male and female distributions. Applying this to a frontal-cropped skull scan produces anatomically plausible counterfactual morphologies in which the brow ridge is attenuated, the chin becomes less projecting, and the zygomatic region narrows for feminization, with the inverse for masculinization. These morphologies fool hold-out classifier","pith_inferences":["A natural stress test: apply AutoFFS to CT-based skulls from diverse ethnic backgrounds. If the deformation hotspots remain anatomically aligned with the known dimorphic regions and the classifiers generalize, the approach would be robust; if not, the learned dimorphism is cohort-specific.","Because the method produces a per-patient deformation field, the same pipeline could in principle be inverted or constrained to generate patient-specific osteotomy and cutting-guide designs — an extension the authors mention only as future work.","The framework effectively treats the sex classifier as a statistical atlas of dimorphism. One could use the resultant deformation directions to visualize and quantify the in-between along the male-female morphology continuum, which might be of independent interest to anthropologists studying craniofacial sex differences.","The reliance on MR-derived bone segmentations raises a question the paper acknowledges: whether the learned dimorphism transfers to CT (the clinical standard). If it does not, the quantitative guidance would need recalibration on CT before use in the operating room."],"forward_implications":["If correct, a surgeon could query 'what would this patient's skull look like as the opposite sex' and obtain a specific, spatially localized map of how much and where the bone should change, rather than relying on qualitative reference morphologies.","The method extends beyond feminization to masculinization (FMS) by flipping the target label, and the authors note the framework could apply to the broader class of gender-affirming facial surgery.","The ensemble strategy, compared to a single classifier, raises the hold-out flip rate from ~71% to 100%, indicating that fooling a diverse set of learned representations yields more robust and population-consistent deformations.","The two new metrics, MFD and MKD, provide a way to evaluate counterfactual shape editing in the absence of ground-truth paired data — a setting common to many medical shape-generation tasks.","The observed concentration of deformations in brow, chin, and zygomatic regions, despite no anatomical priors, suggests the learned classifier representations encode genuine skeletal sexual dimorphism that could be used to build quantitative atlases."],"fun_headline_variants":["Adversarial skulls plan feminization surgery","Skull adversarial attacks guide FFS planning","Counterfactual skull morphs shape feminization surgery","Data-driven FFS planning via adversarial skull deformations"],"cache_read_input_tokens":2304,"weakest_assumption_plain":"The load-bearing premise is that the sex classifiers trained on the Swiss MR cohort capture true skeletal sexual dimorphism, so that pushing a skull across their decision boundary is a clinically meaningful feminization direction rather than a dataset-specific artifact.","fun_headline_variants_meta":{"raw":{"variants":["Adversarial skulls plan feminization surgery","Skull adversarial attacks guide FFS planning","Counterfactual skull morphs shape feminization surgery","Data-driven FFS planning via adversarial skull deformations"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000252,"raw_usage":{"total_tokens":1365,"prompt_tokens":681,"completion_tokens":684,"prompt_tokens_details":{"cached_tokens":256},"prompt_cache_hit_tokens":256,"prompt_cache_miss_tokens":425,"completion_tokens_details":{"reasoning_tokens":624}},"tokens_in":425,"tokens_out":684,"duration_ms":6833,"temperature":1.0,"reasoning_tokens":624,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-02T19:29:26.791078+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Train the same pipeline on a multi-center CT dataset with broad ethnic, age, and sex diversity, and apply it to male and female CT skulls. If the generated feminized skulls no longer flip hold-out CT-trained classifiers at high rates, or if the deformation hotspots move away from the brow, chin, and zygomatic regions that the paper identifies, the 'feminization direction' learned from the MR cohort is a dataset artifact rather than a general skeletal dimorphism.","supporting_citations":[],"review_version":1}