{"id":"bfa933ef-4d65-4b3d-8cbf-4a537240ecd0","arxiv_id":"2606.05561","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":6.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"InfoShield uses TimeAwareMINE to minimize mutual information between speech representations and sensitive attributes, cutting gender inference from 92.6% to 55.5% and age inference from 55.7% to 30.3% while dropping depression F1 by only 6%.","lead":"InfoShield creates speech features for depression screening that leak far less gender and age information by minimizing their mutual information with the features. A smart generalist might read it because privacy concerns currently block many health AI tools from real-world use.","discovery_kind":"unclear","skeptic_critique":{"model":"grok-4.3","headline":"Privacy reductions measured only against fixed classifiers; no test against adaptive or stronger adversaries","rationale":"The reader's weakest_assumption directly identifies the same two load-bearing points (classifier-specific privacy and MI estimator reliability). Because the full text is referenced but the concern is architectural rather than detail-dependent, the UNVERDICTED verdict and LOW confidence remain appropriate.","tokens_in":1696,"tokens_out":304,"duration_ms":18142,"concrete_test":"Retrain gender and age predictors on the InfoShield embeddings using a transformer encoder (same hyper-parameters as the depression model) and report accuracy; if either exceeds 70% the privacy claim requires qualification.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The headline result (gender inference 92.6%→55.5%, age 55.7%→30.3%, F1=0.784) is obtained by training attribute predictors on the released representations. Nothing in the construction or evaluation shows that an adversary who knows the InfoShield objective, has access to the same data distribution, or can choose a different architecture (e.g., a larger transformer or ensemble) cannot recover substantially more attribute information. The TimeAwareMINE estimator is introduced to handle temporal-static misalignment, yet no calibration against known MI values or comparison to alternative estimators (e.g., InfoNCE, NWJ) on held-out sequential speech is reported, leaving open the possibility that the reported MI minimization is overstated.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The paper introduces InfoShield, which minimizes mutual information between learned speech representations and sensitive attributes (gender, age) via an information-theoretic objective while preserving utility for depression classification. It proposes TimeAwareMINE, an extension of MINE using cross-modal attention to address temporal-static misalignment in sequential speech, and reports on the Androids Corpus that the method reduces gender inference from 92.6% to 55.5% and age inference from 55.7% to 30.3% with a 6% F1 drop, reaching F1=0.784 versus prior SOTA of 0.723.","tokens_in":1825,"tokens_out":446,"duration_ms":28865,"significance":"If the privacy claims prove robust, the work would offer a useful alternative to adversarial training and differential privacy for speech-based mental health applications by directly optimizing an information-theoretic privacy-utility tradeoff. The domain-specific estimator for sequential data is a targeted contribution, and the reported gains over SOTA on a real corpus indicate potential practical value if the evaluation holds.","major_comments":[{"comment":"Experimental evaluation: privacy reductions are demonstrated only against the fixed attribute classifiers described; no experiments test whether an adversary aware of the InfoShield objective, with access to the data distribution, or using stronger architectures (e.g., larger transformers or ensembles) can recover substantially more attribute information. This is load-bearing for the central privacy claim.","section":"Experiments"},{"comment":"TimeAwareMINE section: the estimator is introduced to handle sequential speech, yet no calibration against known MI values or head-to-head comparison with alternatives (InfoNCE, NWJ) on held-out sequential speech data is reported, leaving the accuracy of the minimized MI values unverified.","section":"Method"}],"minor_comments":[{"comment":"Abstract: the 6% F1 reduction is stated without an explicit baseline F1 value, making the magnitude of the utility loss harder to interpret directly from the abstract alone.","section":"Abstract"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the constructive feedback. We address each major comment point by point below, with honest assessment of what revisions are feasible.","responses":[{"response":"We agree this is a substantive point for the privacy claims. Our reported results demonstrate reductions against the attribute classifiers used in the evaluation protocol, which is standard for such work, and the mutual information objective provides a distribution-level bound independent of any particular adversary. However, we did not evaluate against adaptive adversaries or stronger models. In revision we will add a limitations paragraph discussing this gap and include new results with an ensemble of attribute classifiers to partially address the concern.","revision_made":"partial","referee_comment":"[Experiments] Experimental evaluation: privacy reductions are demonstrated only against the fixed attribute classifiers described; no experiments test whether an adversary aware of the InfoShield objective, with access to the data distribution, or using stronger architectures (e.g., larger transformers or ensembles) can recover substantially more attribute information. This is load-bearing for the central privacy claim."},{"response":"The referee is correct that no such calibration or comparison is reported. While the cross-modal attention design directly targets the temporal-static misalignment issue in speech, the absence of verification against known MI values or other estimators (InfoNCE, NWJ) leaves the estimator's accuracy unconfirmed. We will add these experiments on held-out sequential speech data in the revised manuscript.","revision_made":"yes","referee_comment":"[Method] TimeAwareMINE section: the estimator is introduced to handle sequential speech, yet no calibration against known MI values or head-to-head comparison with alternatives (InfoNCE, NWJ) on held-out sequential speech data is reported, leaving the accuracy of the minimized MI values unverified."}],"tokens_in":1352,"tokens_out":387,"duration_ms":24667,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The headline result is a drop in gender inference from 92.6% to 55.5% and age from 55.7% to 30.3% on the Androids Corpus, with depression F1 at 0.784 versus prior 0.723 and only 6% utility loss. The paper introduces TimeAwareMINE, a cross-modal attention version of MINE meant to handle temporal-static misalignment in speech sequences.\n\nThat adaptation is the clearest new piece. Standard MINE struggles with frame-level acoustic data paired to static attributes, so the attention mechanism is a reasonable fix for this setting. The work also targets a concrete barrier: demographic leakage that blocks real-world use of speech screening tools. Reporting numbers against an existing baseline gives something concrete to compare.\n\nThe soft spots are in the evaluation. Reductions are shown only against the attribute predictors the authors trained themselves. Nothing indicates the representations would hold up if an adversary knew the InfoShield objective, picked a different architecture, or used an ensemble. The stress-test note on fixed classifiers matches what the abstract shows. No calibration of the MI estimator, no comparison to InfoNCE or NWJ on speech data, and no ablations appear in the provided text. Without those, the claimed minimization could be overstated.\n\nThis is for researchers working on information-theoretic privacy for audio or health applications. A reader already thinking about mutual information bounds in sequential data could extract the TimeAwareMINE idea and test it themselves.\n\nIt deserves peer review. The problem is practical, the approach is a direct attempt to improve on adversarial and DP baselines, and the numbers are at least falsifiable. Expect the referees to ask for adversary robustness and estimator validation.","headline":"InfoShield cuts inference on the tested classifiers but the privacy protection looks fragile without checks against adaptive adversaries or stronger models.","tokens_in":2296,"tokens_out":418,"would_cite":false,"duration_ms":17386,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"InfoShield minimizes mutual information between speech representations and sensitive attributes like gender and age while preserving depression classification performance.","keywords":["privacy-preserving speech","mental health screening","mutual information","depression detection","TimeAwareMINE","gender inference","age inference","information-theoretic optimization"],"falsifier":"A new attribute classifier or adaptive attack that recovers gender or age labels at high accuracy from the released representations would falsify the privacy claim.","tokens_in":2586,"feed_emoji":"🔒","tokens_out":635,"duration_ms":18386,"temperature":0.7,"pith_summary":"The paper aims to resolve the tension between accurate speech-based depression screening and users' privacy concerns over demographic leakage. It does so by training representations that carry less mutual information with attributes such as gender and age. A reader would care because current privacy methods either fail against new attacks or degrade diagnostic utility through blanket noise. The work introduces a specialized mutual-information estimator suited to sequential audio and reports concrete drops in attribute inference alongside only modest loss in screening accuracy.","feed_headline":"InfoShield drops gender inference from speech to 55%","feed_subtitle":"Minimizing mutual information with demographics keeps depression screening F1 at 0.784, only 6% below the unprotected baseline.","key_machinery":"TimeAwareMINE estimator with cross-modal attention that aligns acoustic frames to attribute embeddings in order to produce reliable mutual-information estimates on sequential speech data.","core_discovery":"InfoShield identifies that standard MINE estimators fail on sequential speech because of temporal-static misalignment and therefore introduces TimeAwareMINE, which uses cross-modal attention to align acoustic frames with attribute embeddings. By minimizing the resulting mutual-information estimates between the learned representations and sensitive attributes, the method reduces gender inference accuracy from 92.6% to 55.5% and age inference from 55.7% to 30.3%, while the depression-detection F1 score falls only 6% to 0.784, exceeding the prior state-of-the-art F1 of 0.723.","pith_inferences":["The same mutual-information minimization approach could be tested on other sequential modalities such as video or physiological signals.","The reported privacy gains rest on the specific classifiers used for evaluation; stronger or future attacks might recover more information.","Combining InfoShield with differential privacy mechanisms might yield additive protection without further utility loss."],"forward_implications":["Gender inference accuracy on the protected representations falls to 55.5%.","Age inference accuracy falls to 30.3%.","Depression screening F1 reaches 0.784, outperforming the prior best reported result of 0.723.","The utility penalty remains limited to a 6% F1 reduction relative to an unprotected baseline."],"fun_headline_variants":["InfoShield reduces gender inference from speech to 55%","InfoShield reduces age inference from speech to 30%","Depression screening F1 holds at 0.784 with privacy gains","TimeAwareMINE aligns speech for demographic privacy in screening"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"Lowering inference accuracy on the tested classifiers is treated as evidence of meaningful privacy protection against realistic adversaries.","fun_headline_variants_meta":{"raw":{"variants":["InfoShield reduces gender inference from speech to 55%","InfoShield reduces age inference from speech to 30%","Depression screening F1 holds at 0.784 with privacy gains","TimeAwareMINE aligns speech for demographic privacy in screening"]},"model":"grok-4.3","cost_usd":0.006047,"raw_usage":{"total_tokens":2856,"prompt_tokens":659,"num_sources_used":0,"completion_tokens":66,"cost_in_usd_ticks":60474500,"prompt_tokens_details":{"text_tokens":659,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":2131,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":659,"tokens_out":66,"duration_ms":21821,"temperature":1.0,"reasoning_tokens":2131,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-28T02:01:23.067946+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"A new attribute classifier or adaptive attack that recovers gender or age labels at high accuracy from the released representations would falsify the privacy claim.","supporting_citations":[],"review_version":1}