Saved in:
Bibliographic Details
Main Authors: Wu, Hengyu, Cao, Yang
Format: Preprint
Published: 2025
Subjects:
Online Access:https://arxiv.org/abs/2503.19338
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908510957076480
author Wu, Hengyu
Cao, Yang
author_facet Wu, Hengyu
Cao, Yang
contents As large-scale models such as Large Language Models (LLMs) and Large Multimodal Models (LMMs) see increasing deployment, their privacy risks remain underexplored. Membership Inference Attacks (MIAs), which reveal whether a data point was used in training the target model, are an important technique for exposing or assessing privacy risks and have been shown to be effective across diverse machine learning algorithms. However, despite extensive studies on MIAs in classic models, there remains a lack of systematic surveys addressing their effectiveness and limitations in large-scale models. To address this gap, we provide the first comprehensive review of MIAs targeting LLMs and LMMs, analyzing attacks by model type, adversarial knowledge, and strategy. Unlike prior surveys, we further examine MIAs across multiple stages of the model pipeline, including pre-training, fine-tuning, alignment, and Retrieval-Augmented Generation (RAG). Finally, we identify open challenges and propose future research directions for strengthening privacy resilience in large-scale models.
format Preprint
id arxiv_https___arxiv_org_abs_2503_19338
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Membership Inference Attacks on Large-Scale Models: A Survey
Wu, Hengyu
Cao, Yang
Machine Learning
Cryptography and Security
As large-scale models such as Large Language Models (LLMs) and Large Multimodal Models (LMMs) see increasing deployment, their privacy risks remain underexplored. Membership Inference Attacks (MIAs), which reveal whether a data point was used in training the target model, are an important technique for exposing or assessing privacy risks and have been shown to be effective across diverse machine learning algorithms. However, despite extensive studies on MIAs in classic models, there remains a lack of systematic surveys addressing their effectiveness and limitations in large-scale models. To address this gap, we provide the first comprehensive review of MIAs targeting LLMs and LMMs, analyzing attacks by model type, adversarial knowledge, and strategy. Unlike prior surveys, we further examine MIAs across multiple stages of the model pipeline, including pre-training, fine-tuning, alignment, and Retrieval-Augmented Generation (RAG). Finally, we identify open challenges and propose future research directions for strengthening privacy resilience in large-scale models.
title Membership Inference Attacks on Large-Scale Models: A Survey
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2503.19338