Pith. sign in

REVIEW 1 cited by

Chameleon: Increasing Label-Only Membership Leakage with Adaptive Poisoning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.03838 v2 pith:AFEPRVFR submitted 2023-10-05 cs.LG

classification cs.LG
keywords membershiplabel-onlymodelattacksdatainferencepoisoningadaptive
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

The integration of machine learning (ML) in numerous critical applications introduces a range of privacy concerns for individuals who provide their datasets for model training. One such privacy risk is Membership Inference (MI), in which an attacker seeks to determine whether a particular data sample was included in the training dataset of a model. Current state-of-the-art MI attacks capitalize on access to the model's predicted confidence scores to successfully perform membership inference, and employ data poisoning to further enhance their effectiveness. In this work, we focus on the less explored and more realistic label-only setting, where the model provides only the predicted label on a queried sample. We show that existing label-only MI attacks are ineffective at inferring membership in the low False Positive Rate (FPR) regime. To address this challenge, we propose a new attack Chameleon that leverages a novel adaptive data poisoning strategy and an efficient query selection method to achieve significantly more accurate membership inference than existing label-only attacks, especially at low FPRs.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Privacy Leaks by Adversaries: Adversarial Iterations for Membership Inference Attack

    cs.CR 2025-06 conditional novelty 5.0 of 10

    Counting the iterations required to craft an adversarial example can reveal whether a sample was in the model's training set.

Pith tools