Pith. sign in

REVIEW 2 cited by

User-Level Membership Inference Attack against Metric Embedding Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2203.02077 v2 pith:BVSU7WAW submitted 2022-03-04 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords traininguser-levelattackattackerinferencemembershipsamplebeen
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Membership inference (MI) determines if a sample was part of a victim model training set. Recent development of MI attacks focus on record-level membership inference which limits their application in many real-world scenarios. For example, in the person re-identification task, the attacker (or investigator) is interested in determining if a user's images have been used during training or not. However, the exact training images might not be accessible to the attacker. In this paper, we develop a user-level MI attack where the goal is to find if any sample from the target user has been used during training even when no exact training sample is available to the attacker. We focus on metric embedding learning due to its dominance in person re-identification, where user-level MI attack is more sensible. We conduct an extensive evaluation on several datasets and show that our approach achieves high accuracy on user-level MI task.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Quantifying Training Membership Information in the Hyperspherical Embedding Geometry of Face Recognition Models

    cs.CV 2026-07 conditional novelty 6.0 of 10

    Membership information in face-embedding geometry is controlled mainly by training-set size, not backbone or loss, and same-domain references show the signal shrinks as identity count grows.

  2. CLMIA: Membership Inference Attacks via Unsupervised Contrastive Learning

    cs.LG 2024-11 reject novelty 6.0 of 10

    CLMIA is a membership inference attack that pretrains an attack model on unlabeled classifier posteriors via contrastive learning and fine-tunes it with a small labeled set.

Pith tools