{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:O3UIYRZ2VWFN7ZRCSOTKRQW7IC","short_pith_number":"pith:O3UIYRZ2","schema_version":"1.0","canonical_sha256":"76e88c473aad8adfe62293a6a8c2df40b3fd08a206925f9706cde29f35fdbfd8","source":{"kind":"arxiv","id":"2301.09956","version":1},"attestation_state":"computed","paper":{"title":"Membership Inference of Diffusion Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Hailong Hu, Jun Pang","submitted_at":"2023-01-24T12:34:27Z","abstract_excerpt":"Recent years have witnessed the tremendous success of diffusion models in data synthesis. However, when diffusion models are applied to sensitive data, they also give rise to severe privacy concerns. In this paper, we systematically present the first study about membership inference attacks against diffusion models, which aims to infer whether a sample was used to train the model. Two attack methods are proposed, namely loss-based and likelihood-based attacks. Our attack methods are evaluated on several state-of-the-art diffusion models, over different datasets in relation to privacy-sensitive"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2301.09956","kind":"arxiv","version":1},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.CR","submitted_at":"2023-01-24T12:34:27Z","cross_cats_sorted":["cs.LG"],"title_canon_sha256":"1b9cab074685aa0e794e663bbe8d212f4d99573a0b68822b83e2a9beed87e048","abstract_canon_sha256":"5de7d5bd4dc7e443fdc2ec776abe422874cd6a8758f69442b04917cd8d986416"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T05:35:36.116629Z","signature_b64":"8J49o2b0J7jB60ideIp4EAp6d8kutRBdufCeXH7iDi7CK83xlfheqdFRFVgq1fGZ95h+BtaVsDs93juaIFFFDw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"76e88c473aad8adfe62293a6a8c2df40b3fd08a206925f9706cde29f35fdbfd8","last_reissued_at":"2026-07-05T05:35:36.116137Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T05:35:36.116137Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"Membership Inference of Diffusion Models","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.LG"],"primary_cat":"cs.CR","authors_text":"Hailong Hu, Jun Pang","submitted_at":"2023-01-24T12:34:27Z","abstract_excerpt":"Recent years have witnessed the tremendous success of diffusion models in data synthesis. However, when diffusion models are applied to sensitive data, they also give rise to severe privacy concerns. In this paper, we systematically present the first study about membership inference attacks against diffusion models, which aims to infer whether a sample was used to train the model. Two attack methods are proposed, namely loss-based and likelihood-based attacks. Our attack methods are evaluated on several state-of-the-art diffusion models, over different datasets in relation to privacy-sensitive"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2301.09956","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2301.09956/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2301.09956","created_at":"2026-07-05T05:35:36.116195+00:00"},{"alias_kind":"arxiv_version","alias_value":"2301.09956v1","created_at":"2026-07-05T05:35:36.116195+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2301.09956","created_at":"2026-07-05T05:35:36.116195+00:00"},{"alias_kind":"pith_short_12","alias_value":"O3UIYRZ2VWFN","created_at":"2026-07-05T05:35:36.116195+00:00"},{"alias_kind":"pith_short_16","alias_value":"O3UIYRZ2VWFN7ZRC","created_at":"2026-07-05T05:35:36.116195+00:00"},{"alias_kind":"pith_short_8","alias_value":"O3UIYRZ2","created_at":"2026-07-05T05:35:36.116195+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":4,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2606.20155","citing_title":"NAMESAKES: Probing Identity Memorization in Text-to-Image Models","ref_index":19,"is_internal_anchor":false},{"citing_arxiv_id":"2605.15246","citing_title":"Privacy Evaluation of Generative Models for Trajectory Generation","ref_index":45,"is_internal_anchor":false},{"citing_arxiv_id":"2510.21783","citing_title":"Noise Aggregation Analysis Driven by Small-Noise Injection: Efficient Membership Inference for Diffusion Models","ref_index":17,"is_internal_anchor":false},{"citing_arxiv_id":"2605.11527","citing_title":"FERMI: Exploiting Relations for Membership Inference Against Tabular Diffusion Models","ref_index":12,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC","json":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC.json","graph_json":"https://pith.science/api/pith-number/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/graph.json","events_json":"https://pith.science/api/pith-number/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/events.json","paper":"https://pith.science/paper/O3UIYRZ2"},"agent_actions":{"view_html":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC","download_json":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC.json","view_paper":"https://pith.science/paper/O3UIYRZ2","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2301.09956&json=true","fetch_graph":"https://pith.science/api/pith-number/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/graph.json","fetch_events":"https://pith.science/api/pith-number/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/action/timestamp_anchor","attest_storage":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/action/storage_attestation","attest_author":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/action/author_attestation","sign_citation":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/action/citation_signature","submit_replication":"https://pith.science/pith/O3UIYRZ2VWFN7ZRCSOTKRQW7IC/action/replication_record"}},"created_at":"2026-07-05T05:35:36.116195+00:00","updated_at":"2026-07-05T05:35:36.116195+00:00"}