Browse State-of-the-Art › Inference Attack
Inference Attack
114 papers with code · 0 benchmarks · 2 datasets archive 2025-07-28
Benchmarks archive 2025-07-28
No benchmark for this task in the archive.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
2 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Most implemented papers archive 2025-07-28
30 shown of 114 papers with code (283 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
18 Oct 2016 11 repositories listed Syntology ran 2 of 14 samples · 12 unverifiedWe quantitatively investigate how machine learning models leak information about the individual data records on which they were trained.
-
4 Jun 2018 7 repositories listed Syntology ran 5 of 18 samples · 13 unverified · 2 pointer-only (licence)In addition, we propose the first effective defense mechanisms against such broader class of membership inference attacks that maintain a high level of utility of the ML model.
-
7 Dec 2021 5 repositories listed Syntology ran 5 of 8 samples · 3 unverified · 3 pointer-only (licence)A membership inference attack allows an adversary to query a trained machine learning model to predict whether or not a particular example was contained in the model's training dataset.
-
23 Sep 2019 4 repositories listedSpecifically, given a black-box access to the target classifier, the attacker trains a binary classifier, which takes a data sample's confidence score vector predicted by the target classifier as an input and predicts…
-
15 Sep 2022 3 repositories listed Syntology ran 0 of 3 samples · 3 unverifiedOur large-scale experiments on CLIP demonstrate that individuals used for training can be identified with very high accuracy.
-
19 Sep 2019 3 repositories listedFinally, we discuss the privacy concerns associated with sharing synthetic data produced by GANs and test their ability to withstand a simple membership inference attack.
-
17 Jun 2024 2 repositories listedMembership inference attacks are used as a key tool for disclosure auditing.
-
2 Jan 2024 2 repositories listed Syntology ran 2 of 3 samples · 1 unverified · 3 pointer-only (licence)To mitigate this issue, AI software compression plays a crucial role, which aims to compress model size while keeping high performance.
-
29 Nov 2023 2 repositories listed Syntology ran 4 of 5 samples · 1 unverified · 5 pointer-only (licence)Federated Learning (FL) has been proposed as a privacy-preserving solution for distributed machine learning, particularly in heterogeneous FL settings where clients have varying computational capabilities and thus train…
-
10 Nov 2023 2 repositories listed Syntology ran 5 of 6 samples · 1 unverified · 6 pointer-only (licence)However, this hypothesis heavily relies on the overfitting of target models, which will be mitigated by multiple regularization methods and the generalization of LLMs.
-
15 Dec 2022 2 repositories listedA distribution inference attack aims to infer statistical properties of data used to train machine learning models.
-
11 Aug 2022 2 repositories listed Syntology ran 2 of 3 samples · 1 unverified · 1 pointer-only (licence)By simulating the attack mechanism as the safety test, SafeCompress can automatically compress a big model to a small one following the dynamic sparse training paradigm.
-
13 Sep 2021 2 repositories listed Syntology ran 3 of 14 samples · 11 unverifiedDistribution inference attacks can pose serious risks when models are trained on private data, but are difficult to distinguish from the intrinsic purpose of statistical machine learning -- namely, to produce models…
-
14 Mar 2021 2 repositories listedIn recent years, MIAs have been shown to be effective on various ML models, e.
-
4 Mar 2021 2 repositories listedWe transform (ϵ,δ) to a bound on the Bayesian posterior belief of the adversary assumed by differential privacy concerning the presence of any record in the training dataset.
-
2 Jun 2019 2 repositories listed Syntology ran 3 of 3 samples · 0 unverifiedDifferential privacy bounds disparate vulnerability but can significantly reduce the accuracy of the model.
-
16 Jun 2025 1 repository listedIn this work, we first identify several key pitfalls of the existing unlearning evaluation frameworks, e.
-
11 Jun 2025 1 repository listedMachine Unlearning (MU) aims to update Machine Learning (ML) models following requests to remove training samples and their influences on a trained model efficiently without retraining the original ML model from scratch.
-
6 May 2025 1 repository listedMembership Inference Attacks (MIAs) have recently been employed to determine whether a specific text was part of the pre-training data of Large Language Models (LLMs).
-
6 Feb 2025 1 repository listed Syntology ran 3 of 5 samples · 2 unverified · 5 pointer-only (licence)Document Visual Question Answering (DocVQA) has introduced a new paradigm for end-to-end document understanding, and quickly became one of the standard benchmarks for multimodal LLMs.
-
4 Feb 2025 1 repository listed Syntology ran 3 of 3 samples · 0 unverified · 3 pointer-only (licence)Using this MIA, we perform dataset inference (DI) and find that IARs require as few as six samples to detect dataset membership, compared to 200 for DMs, indicating higher information leakage.
-
30 Jan 2025 1 repository listed Syntology ran 1 of 1 samples · 0 unverifiedWe also develop the first Membership Inference Attack (MIA) for evaluating and auditing the empirical privacy for the problem of LLM steering via activation editing.
-
27 Jan 2025 1 repository listedVision-Language Models (VLMs), built on pre-trained vision encoders and large language models (LLMs), have shown exceptional multi-modal understanding and dialog capabilities, positioning them as catalysts for the next…
-
20 Jan 2025 1 repository listedThis work contributes to the development of privacy-preserving AI systems that align with human cognitive processes of motivated forgetting, offering a robust framework for safeguarding sensitive information and…
-
6 Nov 2024 1 repository listed Syntology ran 4 of 4 samples · 0 unverified · 4 pointer-only (licence)Our method only requires training a small set of models on graphs, while generating a sufficient number of approximated shadow models for attacks.
-
5 Nov 2024 1 repository listed Syntology ran 1 of 10 samples · 9 unverifiedLarge vision-language models (VLLMs) exhibit promising capabilities for processing multi-modal tasks across various application scenarios.
-
4 Nov 2024 1 repository listedThis study addresses these issues by investigating privacy vulnerabilities in radar-based Human Activity Recognition (HAR) systems and proposing a novel method for privacy preservation using Differential Privacy (DP)…
-
30 Oct 2024 1 repository listedTask-oriented semantic communication systems have emerged as a promising approach to achieving efficient and intelligent data transmission, where only information relevant to a specific task is communicated.
-
16 Aug 2024 1 repository listed Syntology ran 10 of 16 samples · 6 unverified · 16 pointer-only (licence)Existing studies have partially addressed this need through an exploration of the pre-training data detection problem, which is an instance of a membership inference attack (MIA).
-
21 Jul 2024 1 repository listed Syntology ran 9 of 10 samples · 1 unverified · 10 pointer-only (licence)Building upon this signal, we introduce a novel attack method called Sequential-metric based Membership Inference Attack (SeqMIA).
Syntology lines on 17 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections