arXiv Machine Learning By Euodia Dodd, Nata\v{s}a Kr\v{c}o, Igor Shilov, Matthew Wicker, Yves-Alexandre de Montjoye

Estimating Model-Level Membership Inference Vulnerability Without Reference Models

Read the original on arXiv Machine Learning →

The paper introduces a method to estimate a model’s vulnerability to the Likelihood Ratio Attack (LiRA) without training reference models, using only the target model’s train and test loss distributions. It shows that LiRA’s per‑sample signal can be decomposed into a variance‑ratio term and a residual mean‑shift term, and that different loss‑distribution shapes dictate which reference‑free proxy to use. Two proxies are presented: the LOSS attack TNR for heavy‑tailed losses and the LOSS attack AUC for symmetric losses, both achieving low RMSE in predicting LiRA TPR across multiple architectures and datasets.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.

arXiv Machine Learning
6d ago

On Reliability of Membership Inference Vulnerability Evaluation

The paper examines the reliability of membership inference attack (MIA) vulnerability evaluation. It identifies two weaknesses: finite‑sample bias from sampling shadow datasets from a fixed superset, and miscalibration when aggregating true positive rates across individuals at very low false positive rates. The authors propose simple fixes that avoid extra computational cost and suggest further improvements with additional computation.

By Joonas J\"alk\"o, Gauri Pradhan, Ossi R\"ais\"a, Antti Honkela
arXiv Machine Learning
Sep 14

Membership Inference via Pairwise Likelihood Ratios

The paper introduces Pairwise Likelihood MIA (PL‑MIA), a unified membership inference attack that combines a Gaussian likelihood‑ratio statistic with population calibration and the Cauchy combination test. PL‑MIA generates p‑values from pairwise comparisons between a query point and reference points, then aggregates these continuous signals using the Cauchy test to preserve evidence strength. Experiments show that PL‑MIA surpasses strong baselines, boosting true positive rates by over 25% in low‑false‑positive settings, thereby validating the theoretical advantages of the proposed statistical framework.

By Shengjie Niu, Zebin Yun, Yeheng Ge, Jian Huang