Membership Inference Attacks Against Vision-Language Models

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Hu, Yuke, Li, Zheng, Liu, Zhihao, Zhang, Yang, Qin, Zhan, Ren, Kui, Chen, Chun
Formato: Preprint
Publicado: 2025
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866917915995930624
author Hu, Yuke
Li, Zheng
Liu, Zhihao
Zhang, Yang
Qin, Zhan
Ren, Kui
Chen, Chun
author_facet Hu, Yuke
Li, Zheng
Liu, Zhihao
Zhang, Yang
Qin, Zhan
Ren, Kui
Chen, Chun
contents Vision-Language Models (VLMs), built on pre-trained vision encoders and large language models (LLMs), have shown exceptional multi-modal understanding and dialog capabilities, positioning them as catalysts for the next technological revolution. However, while most VLM research focuses on enhancing multi-modal interaction, the risks of data misuse and leakage have been largely unexplored. This prompts the need for a comprehensive investigation of such risks in VLMs. In this paper, we conduct the first analysis of misuse and leakage detection in VLMs through the lens of membership inference attack (MIA). In specific, we focus on the instruction tuning data of VLMs, which is more likely to contain sensitive or unauthorized information. To address the limitation of existing MIA methods, we introduce a novel approach that infers membership based on a set of samples and their sensitivity to temperature, a unique parameter in VLMs. Based on this, we propose four membership inference methods, each tailored to different levels of background knowledge, ultimately arriving at the most challenging scenario. Our comprehensive evaluations show that these methods can accurately determine membership status, e.g., achieving an AUC greater than 0.8 targeting a small set consisting of only 5 samples on LLaVA.
format Preprint
id arxiv_https___arxiv_org_abs_2501_18624
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Membership Inference Attacks Against Vision-Language Models
Hu, Yuke
Li, Zheng
Liu, Zhihao
Zhang, Yang
Qin, Zhan
Ren, Kui
Chen, Chun
Cryptography and Security
Artificial Intelligence
Vision-Language Models (VLMs), built on pre-trained vision encoders and large language models (LLMs), have shown exceptional multi-modal understanding and dialog capabilities, positioning them as catalysts for the next technological revolution. However, while most VLM research focuses on enhancing multi-modal interaction, the risks of data misuse and leakage have been largely unexplored. This prompts the need for a comprehensive investigation of such risks in VLMs. In this paper, we conduct the first analysis of misuse and leakage detection in VLMs through the lens of membership inference attack (MIA). In specific, we focus on the instruction tuning data of VLMs, which is more likely to contain sensitive or unauthorized information. To address the limitation of existing MIA methods, we introduce a novel approach that infers membership based on a set of samples and their sensitivity to temperature, a unique parameter in VLMs. Based on this, we propose four membership inference methods, each tailored to different levels of background knowledge, ultimately arriving at the most challenging scenario. Our comprehensive evaluations show that these methods can accurately determine membership status, e.g., achieving an AUC greater than 0.8 targeting a small set consisting of only 5 samples on LLaVA.
title Membership Inference Attacks Against Vision-Language Models
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2501.18624