{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/understanding-membership-inferences-on-well","title":"Understanding Membership Inferences on Well-Generalized Learning Models","arxiv_id":"1802.04889","date":"2018-02-13","proceeding":null,"authors":["Yunhui Long","Vincent Bindschaedler","Lei Wang","Diyue Bu","Xiao-Feng Wang","Haixu Tang","Carl A. Gunter","Kai Chen"],"abstract":"Membership Inference Attack (MIA) determines the presence of a record in a\nmachine learning model's training data by querying the model. Prior work has\nshown that the attack is feasible when the model is overfitted to its training\ndata or when the adversary controls the training algorithm. However, when the\nmodel is not overfitted and the adversary does not control the training\nalgorithm, the threat is not well understood. In this paper, we report a study\nthat discovers overfitting to be a sufficient but not a necessary condition for\nan MIA to succeed. More specifically, we demonstrate that even a\nwell-generalized model contains vulnerable instances subject to a new\ngeneralized MIA (GMIA). In GMIA, we use novel techniques for selecting\nvulnerable instances and detecting their subtle influences ignored by\noverfitting metrics. Specifically, we successfully identify individual records\nwith high precision in real-world datasets by querying black-box machine\nlearning models. Further we show that a vulnerable record can even be\nindirectly attacked by querying other related records and existing\ngeneralization techniques are found to be less effective in protecting the\nvulnerable instances. Our findings sharpen the understanding of the fundamental\ncause of the problem: the unique influences the training instance may have on\nthe model.","url_abs":"http://arxiv.org/abs/1802.04889v1","url_pdf":"http://arxiv.org/pdf/1802.04889v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"understanding-membership-inferences-on-well","repo_url":"https://github.com/BielStela/membership_inference","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"none","reach":{"status":"ok","spdx":"GPL-3.0"}}],"tasks":[{"task_slug":"machine-learning","task_name":"BIG-bench Machine Learning"},{"task_slug":"inference-attack","task_name":"Inference Attack"},{"task_slug":"membership-inference-attack","task_name":"Membership Inference Attack"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":"https://syntology.ai/paper/1802.04889","atlas_url":"https://app.syntology.ai/?focus=1802.04889","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}