{"url":"/task/membership-inference-attack","name":"Membership Inference Attack","slug":"membership-inference-attack","description_markdown":null,"categories":[{"name":"Computer Vision","url":"/area/computer-vision"},{"name":"Methodology","url":"/area/methodology"},{"name":"Miscellaneous","url":"/area/miscellaneous"}],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"derived"},"counts":{"papers_tagged":186,"papers_with_code":78,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":0,"subtasks":0,"parent_tasks":1},"benchmarks":[],"datasets":[],"subtasks":[],"parent_tasks":[{"url":"/task/privacy-preserving-deep-learning","name":"Privacy Preserving Deep Learning"}],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":30,"of":78,"tagged_in_all":186,"items":[{"url":"/paper/membership-inference-attacks-against-machine","title":"Membership Inference Attacks against Machine Learning Models","date":"2016-10-18","arxiv_id":"1610.05820","repositories_listed":11,"syntology":{"n":14,"n_ran":2,"n_unverified":12,"n_pointer_only":0}},{"url":"/paper/ml-leaks-model-and-data-independent","title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models","date":"2018-06-04","arxiv_id":"1806.01246","repositories_listed":7,"syntology":{"n":18,"n_ran":5,"n_unverified":13,"n_pointer_only":2}},{"url":"/paper/membership-inference-attacks-from-first","title":"Membership Inference Attacks From First Principles","date":"2021-12-07","arxiv_id":"2112.03570","repositories_listed":5,"syntology":{"n":8,"n_ran":5,"n_unverified":3,"n_pointer_only":3}},{"url":"/paper/memguard-defending-against-black-box","title":"MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples","date":"2019-09-23","arxiv_id":"1909.10594","repositories_listed":4,"syntology":null},{"url":"/paper/synthesis-of-realistic-ecg-using-generative","title":"Synthesis of Realistic ECG using Generative Adversarial Networks","date":"2019-09-19","arxiv_id":"1909.09150","repositories_listed":3,"syntology":null},{"url":"/paper/do-parameters-reveal-more-than-loss-for","title":"Do Parameters Reveal More than Loss for Membership Inference?","date":"2024-06-17","arxiv_id":"2406.11544","repositories_listed":2,"syntology":null},{"url":"/paper/safety-and-performance-why-not-both-bi-1","title":"Safety and Performance, Why Not Both? Bi-Objective Optimized Model Compression against Heterogeneous Attacks Toward AI Software Deployment","date":"2024-01-02","arxiv_id":"2401.00996","repositories_listed":2,"syntology":{"n":3,"n_ran":2,"n_unverified":1,"n_pointer_only":3}},{"url":"/paper/addressing-membership-inference-attack-in","title":"Privacy and Accuracy Implications of Model Complexity and Integration in Heterogeneous Federated Learning","date":"2023-11-29","arxiv_id":"2311.17750","repositories_listed":2,"syntology":{"n":5,"n_ran":4,"n_unverified":1,"n_pointer_only":5}},{"url":"/paper/practical-membership-inference-attacks","title":"Practical Membership Inference Attacks against Fine-tuned Large Language Models via Self-prompt Calibration","date":"2023-11-10","arxiv_id":"2311.06062","repositories_listed":2,"syntology":{"n":6,"n_ran":5,"n_unverified":1,"n_pointer_only":6}},{"url":"/paper/safety-and-performance-why-not-both-bi","title":"Safety and Performance, Why not Both? Bi-Objective Optimized Model Compression toward AI Software Deployment","date":"2022-08-11","arxiv_id":"2208.05969","repositories_listed":2,"syntology":{"n":3,"n_ran":2,"n_unverified":1,"n_pointer_only":1}},{"url":"/paper/membership-inference-attacks-on-machine","title":"Membership Inference Attacks on Machine Learning: A Survey","date":"2021-03-14","arxiv_id":"2103.07853","repositories_listed":2,"syntology":null},{"url":"/paper/190600389","title":"Disparate Vulnerability to Membership Inference Attacks","date":"2019-06-02","arxiv_id":"1906.00389","repositories_listed":2,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/apollo-a-posteriori-label-only-membership","title":"Apollo: A Posteriori Label-Only Membership Inference Attack Towards Machine Unlearning","date":"2025-06-11","arxiv_id":"2506.09923","repositories_listed":1,"syntology":null},{"url":"/paper/automatic-calibration-for-membership","title":"Automatic Calibration for Membership Inference Attack on Large Language Models","date":"2025-05-06","arxiv_id":"2505.03392","repositories_listed":1,"syntology":null},{"url":"/paper/docmia-document-level-membership-inference","title":"DocMIA: Document-Level Membership Inference Attacks against DocVQA Models","date":"2025-02-06","arxiv_id":"2502.03692","repositories_listed":1,"syntology":{"n":5,"n_ran":3,"n_unverified":2,"n_pointer_only":5}},{"url":"/paper/privacy-attacks-on-image-autoregressive","title":"Privacy Attacks on Image AutoRegressive Models","date":"2025-02-04","arxiv_id":"2502.02514","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":3}},{"url":"/paper/riddle-me-this-stealthy-membership-inference","title":"Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented Generation","date":"2025-02-01","arxiv_id":"2502.00306","repositories_listed":1,"syntology":null},{"url":"/paper/differentially-private-steering-for-large","title":"Differentially Private Steering for Large Language Model Alignment","date":"2025-01-30","arxiv_id":"2501.18532","repositories_listed":1,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/membership-inference-attacks-against-vision","title":"Membership Inference Attacks Against Vision-Language Models","date":"2025-01-27","arxiv_id":"2501.18624","repositories_listed":1,"syntology":null},{"url":"/paper/technical-report-for-the-forgotten-by-design","title":"Technical Report for the Forgotten-by-Design Project: Targeted Obfuscation for Machine Learning","date":"2025-01-20","arxiv_id":"2501.11525","repositories_listed":1,"syntology":null},{"url":"/paper/membership-inference-attacks-against-large","title":"Membership Inference Attacks against Large Vision-Language Models","date":"2024-11-05","arxiv_id":"2411.02902","repositories_listed":1,"syntology":{"n":10,"n_ran":1,"n_unverified":9,"n_pointer_only":0}},{"url":"/paper/differentially-private-integrated-decision","title":"Differentially Private Integrated Decision Gradients (IDG-DP) for Radar-based Human Activity Recognition","date":"2024-11-04","arxiv_id":"2411.02099","repositories_listed":1,"syntology":null},{"url":"/paper/mia-tuner-adapting-large-language-models-as","title":"MIA-Tuner: Adapting Large Language Models as Pre-training Text Detector","date":"2024-08-16","arxiv_id":"2408.08661","repositories_listed":1,"syntology":{"n":16,"n_ran":10,"n_unverified":6,"n_pointer_only":16}},{"url":"/paper/seqmia-sequential-metric-based-membership","title":"SeqMIA: Sequential-Metric Based Membership Inference Attack","date":"2024-07-21","arxiv_id":"2407.15098","repositories_listed":1,"syntology":{"n":10,"n_ran":9,"n_unverified":1,"n_pointer_only":10}},{"url":"/paper/a-method-to-facilitate-membership-inference","title":"A Method to Facilitate Membership Inference Attacks in Deep Learning Models","date":"2024-07-02","arxiv_id":"2407.01919","repositories_listed":1,"syntology":{"n":8,"n_ran":5,"n_unverified":3,"n_pointer_only":0}},{"url":"/paper/rwku-benchmarking-real-world-knowledge","title":"RWKU: Benchmarking Real-World Knowledge Unlearning for Large Language Models","date":"2024-06-16","arxiv_id":"2406.10890","repositories_listed":1,"syntology":{"n":2,"n_ran":1,"n_unverified":1,"n_pointer_only":2}},{"url":"/paper/mosaic-memory-fuzzy-duplication-in-copyright","title":"The Mosaic Memory of Large Language Models","date":"2024-05-24","arxiv_id":"2405.15523","repositories_listed":1,"syntology":{"n":16,"n_ran":16,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/data-contamination-calibration-for-black-box","title":"Data Contamination Calibration for Black-box LLMs","date":"2024-05-20","arxiv_id":"2405.11930","repositories_listed":1,"syntology":{"n":8,"n_ran":6,"n_unverified":2,"n_pointer_only":0}},{"url":"/paper/glira-black-box-membership-inference-attack","title":"GLiRA: Black-Box Membership Inference Attack via Knowledge Distillation","date":"2024-05-13","arxiv_id":"2405.07562","repositories_listed":1,"syntology":null},{"url":"/paper/shake-to-leak-fine-tuning-diffusion-models","title":"Shake to Leak: Fine-tuning Diffusion Models Can Amplify the Generative Privacy Risk","date":"2024-03-14","arxiv_id":"2403.09450","repositories_listed":1,"syntology":{"n":3,"n_ran":2,"n_unverified":1,"n_pointer_only":2}}],"syntology_records":19,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}