Privacy-Preserving Federated Digital Twin Intelligence for Trustworthy Multimodal Disease Prediction Using Explainable Foundation Models

Main Article Content

Ganesh Dagadu Puri, Aarti S.Gaikwad, Supriya Sabale, Vinod V. Kimbahune, Mansi Bhonsle, Sachin Arun Thanekar

Abstract

Clinical risk models seldom fail for want of a better algorithm. They fail because the records that would make them dependable sit behind institutional and statutory walls, because a single snapshot cannot describe a physiology that shifts within hours and because a clinician will not act on a number that arrives with no reason attached. This paper treats those three failures as one design problem. We present FedTwin-X, a federated architecture in which every participating hospital maintains a patient digital twin: a persistent latent state assembled from irregular vital-sign and laboratory streams, chest radiographs, twelve-lead electrocardiograms and free-text notes. Modality-specific foundation encoders stay frozen throughout; only low-rank adapters are trained and only those adapters cross the network. Updates are protected by secure aggregation together with client-level differential privacy under Rényi accounting, so no individual site contribution is ever observable in the clear. Because the trainable parameter counts falls by more than an order of magnitude, the noise required for a given privacy budget falls with it, a coupling that turns parameter-efficient adaptation from a convenience into a privacy mechanism. Each prediction is emitted alongside four artefacts: a modality attribution, a temporal attribution over the twin trajectory, a sparse activation over forty-eight clinical concepts and a counterfactual roll-out of the twin under a hypothetical intervention. We describe an evaluation over three cohorts drawn from MIMIC-IV, MIMIC-CXR, the eICU Collaborative Research Database and PTB-XL, partitioned into twenty-two clients along genuine institutional boundaries. On forty-eight-hour deterioration prediction the architecture is designed to operate within roughly two AUROC points of an unconstrained centralised model while halving calibration error and reducing uplink traffic by a factor of twenty-two.

Article Details

Section
Articles