Pith. sign in

REVIEW 15 cited by

LOGAN: Membership Inference Attacks Against Generative Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1705.07663 v4 pith:6ELPMYF5 submitted 2017-05-22 cs.CR cs.LG

classification cs.CRcs.LG
keywords generativeattacksmodelsmodeltrainingdatasetsdistributioninference
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Generative models estimate the underlying distribution of a dataset to generate realistic samples according to that distribution. In this paper, we present the first membership inference attacks against generative models: given a data point, the adversary determines whether or not it was used to train the model. Our attacks leverage Generative Adversarial Networks (GANs), which combine a discriminative and a generative model, to detect overfitting and recognize inputs that were part of training datasets, using the discriminator's capacity to learn statistical differences in distributions. We present attacks based on both white-box and black-box access to the target model, against several state-of-the-art generative models, over datasets of complex representations of faces (LFW), objects (CIFAR-10), and medical images (Diabetic Retinopathy). We also discuss the sensitivity of the attacks to different training parameters, and their robustness against mitigation strategies, finding that defenses are either ineffective or lead to significantly worse performances of the generative models in terms of training stability and/or sample quality.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 15 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Cross-Flow Correlations Survive Synthesis: Measuring Source-Level Privacy Leakage in Synthetic Network Traces

    cs.CR 2025-08 conditional novelty 8.0 of 10

    Synthetic network generators preserve cross-flow correlations enabling source-level membership inference, shown via the TraceBleed attack across five datasets and six generators.

  2. Single-Sample Black-Box Membership Inference Attack against Vision-Language Models via Cross-modal Semantic Alignment

    cs.CV 2026-05 unverdicted novelty 7.0 of 10

    A cross-modal alignment attack achieves AUC 0.821 for single-sample black-box membership inference on VLMs such as LLaVA-1.5 by quantifying image-generated caption similarity.

  3. Generalization and Memorization in Rectified Flow

    cs.LG 2026-03 accept novelty 7.0 of 10

    Rectified Flow models peak in membership-inference vulnerability at the flow midpoint under uniform training; U-shaped timestep sampling suppresses memorization without harming FID.

  4. Noise Aggregation Analysis Driven by Small-Noise Injection: Efficient Membership Inference for Diffusion Models

    cs.CV 2025-10 unverdicted novelty 7.0 of 10

    Introduces noise aggregation analysis with single-step small-noise injection to enable efficient and accurate membership inference attacks on diffusion models.

  5. Cascading and Proxy Membership Inference Attacks

    cs.CR 2025-07 conditional novelty 7.0 of 10

    CMIA cascades conditional shadow training to exploit membership dependencies, and PMIA uses proxy data to approximate Bayesian membership odds, both substantially outperforming prior MIAs in low false-positive regimes.

  6. SoK: Can Synthetic Images Replace Real Data? A Survey of Utility and Privacy of Synthetic Image Generation

    cs.CR 2025-06 conditional novelty 7.0 of 10

    A systematic survey and benchmark showing that diffusion-based synthetic data can achieve better utility-privacy tradeoffs than DP-SGD on real data for some image classifiers, with the best release strategy depending ...

  7. Vid-SME: Membership Inference Attacks against Large Video Understanding Models

    cs.CV 2025-05 reject novelty 7.0 of 10

    Vid-SME computes Sharma-Mittal entropy differences between natural and reversed video frame sequences to infer training membership in video understanding LLMs, but its effectiveness is confounded by member/non-member ...

  8. Advancing the State-of-the-Art in Empirical Privacy Auditing

    cs.LG 2026-06 unverdicted novelty 6.0 of 10

    Proposes high-temperature synthetic canaries and auxiliary-model auditing to improve empirical privacy measurement for LLM fine-tuning and synthetic data generation.

  9. DCMI: A Differential Calibration Membership Inference Attack Against Retrieval-Augmented Generation

    cs.CR 2025-09 conditional novelty 6.0 of 10

    DCMI infers RAG database membership by subtracting the system's yes-probability on a perturbed query from the original query, cancelling the interference of non-member retrieved documents.

  10. Evaluating the Dynamics of Membership Privacy in Deep Learning

    cs.LG 2025-07 conditional novelty 6.0 of 10

    Per-sample membership vulnerability is established early in training, especially for hard-to-learn examples, and can be tracked on an FPR-TPR plane.

  11. Hey, That's My Data! Token-Only Dataset Inference in Large Language Models

    cs.CL 2025-06 unverdicted novelty 6.0 of 10

    CatShift detects training data membership in LLMs by comparing output shifts induced by fine-tuning on member versus non-member data, relying on catastrophic forgetting without requiring logit access.

  12. Quantifying the Privacy of Counterfactuals by Leveraging Membership Inference Attacks Against Synthetic Data

    cs.LG 2026-06 unverdicted novelty 5.0 of 10

    Membership inference attacks adapted from synthetic data succeed on counterfactuals using only the counterfactuals themselves, without model access.

  13. When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning

    cs.CR 2025-06 conditional novelty 5.0 of 10

    Membership inference against contrastive encoders is more accurate for larger frameworks and backbones, and a lightweight likelihood attack based on feature-vector p-norms matches or beats prior attacks with fewer queries.

  14. An Out-Of-Distribution Membership Inference Attack Approach for Cross-Domain Graph Attacks

    cs.LG 2025-05 reject novelty 5.0 of 10

    GOOD-MIA combines invariant risk minimization, a graph information bottleneck, and risk extrapolation to run membership inference attacks against graph neural networks across different data domains.

  15. Synthetic Tabular Data: Methods, Attacks and Defenses

    cs.LG 2025-06 conditional novelty 1.0 of 10

    A review of tabular synthetic data generation, privacy attacks, and defenses, whose central message is that synthetic data alone does not guarantee privacy.

Pith tools