{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/low-cost-high-power-membership-inference-by","title":"Low-Cost High-Power Membership Inference Attacks","arxiv_id":"2312.03262","date":"2023-12-06","proceeding":null,"authors":["Sajjad Zarifzadeh","Philippe Liu","Reza Shokri"],"abstract":"Membership inference attacks aim to detect if a particular data point was used in training a model. We design a novel statistical test to perform robust membership inference attacks (RMIA) with low computational overhead. We achieve this by a fine-grained modeling of the null hypothesis in our likelihood ratio tests, and effectively leveraging both reference models and reference population data samples. RMIA has superior test power compared with prior methods, throughout the TPR-FPR curve (even at extremely low FPR, as low as 0). Under computational constraints, where only a limited number of pre-trained reference models (as few as 1) are available, and also when we vary other elements of the attack (e.g., data distribution), our method performs exceptionally well, unlike prior attacks that approach random guessing. RMIA lays the groundwork for practical yet accurate data privacy risk assessment in machine learning.","url_abs":"https://arxiv.org/abs/2312.03262v3","url_pdf":"https://arxiv.org/pdf/2312.03262v3.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"low-cost-high-power-membership-inference-by","repo_url":"https://github.com/privacytrustlab/ml_privacy_meter","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"tf","reach":null}],"tasks":[{"task_slug":"inference-attack","task_name":"Inference Attack"},{"task_slug":"membership-inference-attack","task_name":"Membership Inference Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/2312.03262","atlas_url":"https://app.syntology.ai/?focus=2312.03262","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2312.03262"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-25T09:33:49+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/privacytrustlab/ml_privacy_meter","reach":null}],"summary":{"ran_draft_wrong":4,"ran_fixture":1},"by_repo_kind":{"official":{"samples":5,"ran":5,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":0,"samples":[{"code_sha256_prefix":"a59ef22f46f6ec25","entry":"get_out_ref_signals","repo":"privacytrustlab/ml_privacy_meter","repo_kind":"official","path":"modules/mia/attacks/rmia.py","file_url":"https://github.com/privacytrustlab/ml_privacy_meter/blob/HEAD/modules/mia/attacks/rmia.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"a59ef22f46f6ec25"}},{"code_sha256_prefix":"1a14d18b0056ba8c","entry":"get_out_ref_signals","repo":"privacytrustlab/ml_privacy_meter","repo_kind":"official","path":"modules/mia/attacks/rmia.py","file_url":"https://github.com/privacytrustlab/ml_privacy_meter/blob/HEAD/modules/mia/attacks/rmia.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"1a14d18b0056ba8c"}},{"code_sha256_prefix":"fe1c2a594fa84534","entry":"run_rmia","repo":"privacytrustlab/ml_privacy_meter","repo_kind":"official","path":"modules/mia/attacks/rmia.py","file_url":"https://github.com/privacytrustlab/ml_privacy_meter/blob/HEAD/modules/mia/attacks/rmia.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"fe1c2a594fa84534"}},{"code_sha256_prefix":"17cb47e99a35676a","entry":"run_rmia","repo":"privacytrustlab/ml_privacy_meter","repo_kind":"official","path":"modules/mia/attacks/rmia.py","file_url":"https://github.com/privacytrustlab/ml_privacy_meter/blob/HEAD/modules/mia/attacks/rmia.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"17cb47e99a35676a"}},{"code_sha256_prefix":"21499adc7b6b9d87","entry":"tune_offline_a","repo":"privacytrustlab/ml_privacy_meter","repo_kind":"official","path":"modules/mia/attacks/rmia.py","file_url":"https://github.com/privacytrustlab/ml_privacy_meter/blob/HEAD/modules/mia/attacks/rmia.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"MIT","inline_ok":true,"mcp_get_code":{"code_sha256":"21499adc7b6b9d87"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}