Browse State-of-the-Art › Membership Inference Attack
Membership Inference Attack
78 papers with code · 0 benchmarks · 0 datasets archive 2025-07-28
Benchmarks archive 2025-07-28
No benchmark for this task in the archive.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
No dataset record in the archive lists this task.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Parent tasks archive 2025-07-28
Most implemented papers archive 2025-07-28
30 shown of 78 papers with code (186 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
18 Oct 2016 11 repositories listed Syntology ran 2 of 14 samples · 12 unverifiedWe quantitatively investigate how machine learning models leak information about the individual data records on which they were trained.
-
4 Jun 2018 7 repositories listed Syntology ran 5 of 18 samples · 13 unverified · 2 pointer-only (licence)In addition, we propose the first effective defense mechanisms against such broader class of membership inference attacks that maintain a high level of utility of the ML model.
-
7 Dec 2021 5 repositories listed Syntology ran 5 of 8 samples · 3 unverified · 3 pointer-only (licence)A membership inference attack allows an adversary to query a trained machine learning model to predict whether or not a particular example was contained in the model's training dataset.
-
23 Sep 2019 4 repositories listedSpecifically, given a black-box access to the target classifier, the attacker trains a binary classifier, which takes a data sample's confidence score vector predicted by the target classifier as an input and predicts…
-
19 Sep 2019 3 repositories listedFinally, we discuss the privacy concerns associated with sharing synthetic data produced by GANs and test their ability to withstand a simple membership inference attack.
-
17 Jun 2024 2 repositories listedMembership inference attacks are used as a key tool for disclosure auditing.
-
2 Jan 2024 2 repositories listed Syntology ran 2 of 3 samples · 1 unverified · 3 pointer-only (licence)To mitigate this issue, AI software compression plays a crucial role, which aims to compress model size while keeping high performance.
-
29 Nov 2023 2 repositories listed Syntology ran 4 of 5 samples · 1 unverified · 5 pointer-only (licence)Federated Learning (FL) has been proposed as a privacy-preserving solution for distributed machine learning, particularly in heterogeneous FL settings where clients have varying computational capabilities and thus train…
-
10 Nov 2023 2 repositories listed Syntology ran 5 of 6 samples · 1 unverified · 6 pointer-only (licence)However, this hypothesis heavily relies on the overfitting of target models, which will be mitigated by multiple regularization methods and the generalization of LLMs.
-
11 Aug 2022 2 repositories listed Syntology ran 2 of 3 samples · 1 unverified · 1 pointer-only (licence)By simulating the attack mechanism as the safety test, SafeCompress can automatically compress a big model to a small one following the dynamic sparse training paradigm.
-
14 Mar 2021 2 repositories listedIn recent years, MIAs have been shown to be effective on various ML models, e.
-
2 Jun 2019 2 repositories listed Syntology ran 3 of 3 samples · 0 unverifiedDifferential privacy bounds disparate vulnerability but can significantly reduce the accuracy of the model.
-
11 Jun 2025 1 repository listedMachine Unlearning (MU) aims to update Machine Learning (ML) models following requests to remove training samples and their influences on a trained model efficiently without retraining the original ML model from scratch.
-
6 May 2025 1 repository listedMembership Inference Attacks (MIAs) have recently been employed to determine whether a specific text was part of the pre-training data of Large Language Models (LLMs).
-
6 Feb 2025 1 repository listed Syntology ran 3 of 5 samples · 2 unverified · 5 pointer-only (licence)Document Visual Question Answering (DocVQA) has introduced a new paradigm for end-to-end document understanding, and quickly became one of the standard benchmarks for multimodal LLMs.
-
4 Feb 2025 1 repository listed Syntology ran 3 of 3 samples · 0 unverified · 3 pointer-only (licence)Using this MIA, we perform dataset inference (DI) and find that IARs require as few as six samples to detect dataset membership, compared to 200 for DMs, indicating higher information leakage.
-
1 Feb 2025 1 repository listedRetrieval-Augmented Generation (RAG) enables Large Language Models (LLMs) to generate grounded responses by leveraging external knowledge databases without altering model parameters.
-
30 Jan 2025 1 repository listed Syntology ran 1 of 1 samples · 0 unverifiedWe also develop the first Membership Inference Attack (MIA) for evaluating and auditing the empirical privacy for the problem of LLM steering via activation editing.
-
27 Jan 2025 1 repository listedVision-Language Models (VLMs), built on pre-trained vision encoders and large language models (LLMs), have shown exceptional multi-modal understanding and dialog capabilities, positioning them as catalysts for the next…
-
20 Jan 2025 1 repository listedThis work contributes to the development of privacy-preserving AI systems that align with human cognitive processes of motivated forgetting, offering a robust framework for safeguarding sensitive information and…
-
5 Nov 2024 1 repository listed Syntology ran 1 of 10 samples · 9 unverifiedLarge vision-language models (VLLMs) exhibit promising capabilities for processing multi-modal tasks across various application scenarios.
-
4 Nov 2024 1 repository listedThis study addresses these issues by investigating privacy vulnerabilities in radar-based Human Activity Recognition (HAR) systems and proposing a novel method for privacy preservation using Differential Privacy (DP)…
-
16 Aug 2024 1 repository listed Syntology ran 10 of 16 samples · 6 unverified · 16 pointer-only (licence)Existing studies have partially addressed this need through an exploration of the pre-training data detection problem, which is an instance of a membership inference attack (MIA).
-
21 Jul 2024 1 repository listed Syntology ran 9 of 10 samples · 1 unverified · 10 pointer-only (licence)Building upon this signal, we introduce a novel attack method called Sequential-metric based Membership Inference Attack (SeqMIA).
-
2 Jul 2024 1 repository listed Syntology ran 5 of 8 samples · 3 unverifiedModern machine learning (ML) ecosystems offer a surging number of ML frameworks and code repositories that can greatly facilitate the development of ML models.
-
16 Jun 2024 1 repository listed Syntology ran 1 of 2 samples · 1 unverified · 2 pointer-only (licence)Large language models (LLMs) inevitably memorize sensitive, copyrighted, and harmful knowledge from the training corpus; therefore, it is crucial to erase this knowledge from the models.
-
24 May 2024 1 repository listed Syntology ran 16 of 16 samples · 0 unverifiedAs Large Language Models (LLMs) become widely adopted, understanding how they learn from, and memorize, training data becomes crucial.
-
20 May 2024 1 repository listed Syntology ran 6 of 8 samples · 2 unverifiedThe rapid advancements of Large Language Models (LLMs) tightly associate with the expansion of the training data size.
-
13 May 2024 1 repository listedWe observe that the knowledge distillation significantly improves the efficiency of likelihood ratio of membership inference attack, especially in the black-box setting, i.
-
14 Mar 2024 1 repository listed Syntology ran 2 of 3 samples · 1 unverified · 2 pointer-only (licence)While diffusion models have recently demonstrated remarkable progress in generating realistic images, privacy risks also arise: published models or APIs could generate training images and thus leak privacy-sensitive…
Syntology lines on 19 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections