Image autoregressive models leak substantially more training data than diffusion models under membership inference, dataset inference with as few as 4 samples, and data extraction attacks.
Previous works (Maini et al., 2024; Dubi´nski et al., 2025) aggregate signal from many MIAs to yield a stronger attack
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CV 1years
2025 1verdicts
UNVERDICTED 1representative citing papers
citing papers explorer
-
Privacy Attacks on Image AutoRegressive Models
Image autoregressive models leak substantially more training data than diffusion models under membership inference, dataset inference with as few as 4 samples, and data extraction attacks.