arXiv Machine Learning

Causal Evaluation of Membership Inference Attacks

arXiv:2602. 02819v4 Announce Type: replace Abstract: Membership Inference Attacks (MIAs) aim to distinguish training points (members) from unseen data (non-members), and are widely used to quantify memorization and assess privacy risks.

arXiv Machine Learning
Sep 14

Membership Inference via Pairwise Likelihood Ratios

The paper introduces Pairwise Likelihood MIA (PL‑MIA), a unified membership inference attack that combines a Gaussian likelihood‑ratio statistic with population calibration and the Cauchy combination test. PL‑MIA generates p‑values from pairwise comparisons between a query point and reference points, then aggregates these continuous signals using the Cauchy test to preserve evidence strength. Experiments show that PL‑MIA surpasses strong baselines, boosting true positive rates by over 25% in low‑false‑positive settings, thereby validating the theoretical advantages of the proposed statistical framework.

By Shengjie Niu, Zebin Yun, Yeheng Ge, Jian Huang
arXiv Machine Learning
Sep 11

Adaptive Diffusion Freezing: Privacy-preserving Diffusion Models Against Membership Inference Attacks

Adaptive Diffusion Freezing (ADF) is a new privacy‑preserving framework for diffusion models that protects against membership inference attacks (MIAs). It uses cross‑timestep adaptive freezing training, where a mask matrix controls which data subsets participate at each diffusion timestep, reducing over‑memorization and aligning model behavior for member and non‑member samples. A pretraining‑based risk‑aware freezing policy estimates MIA risk and suppresses high‑risk subset‑timestep pairs, achieving a superior privacy‑utility‑efficiency trade‑off across multiple datasets.

By Jialu Guo, Xiao Han, Junjie Wu
arXiv AI
Sep 18

Batch Normalization Amplifies Memorization and Privacy Risks

Batch Normalization (BN) is widely used to speed up and stabilize deep neural network training, yet its effect on privacy and memorization has been largely unexplored. This study shows that BN significantly increases the memorization of atypical or outlier samples, as evidenced by unintended memorization, per-sample influence, and heightened susceptibility to membership inference attacks across multiple datasets and architectures. A mechanistic analysis of the BN backward pass reveals that BN amplifies the per‑step margin growth of outlier samples during training, thereby intensifying their influence.

By Ngoc Phu Doan, Chongyan Gu, Ihsen Alouani