Practical Bayes-Optimal Membership Inference Attacks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Lassila, Marcus, Östman, Johan, Ngo, Khac-Hoang, Amat, Alexandre Graell i
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908616127152128
author Lassila, Marcus
Östman, Johan
Ngo, Khac-Hoang
Amat, Alexandre Graell i
author_facet Lassila, Marcus
Östman, Johan
Ngo, Khac-Hoang
Amat, Alexandre Graell i
contents We develop practical and theoretically grounded membership inference attacks (MIAs) against both independent and identically distributed (i.i.d.) data and graph-structured data. Building on the Bayesian decision-theoretic framework of Sablayrolles et al., we derive the Bayes-optimal membership inference rule for node-level MIAs against graph neural networks, addressing key open questions about optimal query strategies in the graph setting. We introduce BASE and G-BASE, tractable approximations of the Bayes-optimal membership inference. G-BASE achieves superior performance compared to previously proposed classifier-based node-level MIA attacks. BASE, which is also applicable to non-graph data, matches or exceeds the performance of prior state-of-the-art MIAs, such as LiRA and RMIA, at a significantly lower computational cost. Finally, we show that BASE and RMIA are equivalent under a specific hyperparameter setting, providing a principled, Bayes-optimal justification for the RMIA attack.
format Preprint
id arxiv_https___arxiv_org_abs_2505_24089
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Practical Bayes-Optimal Membership Inference Attacks
Lassila, Marcus
Östman, Johan
Ngo, Khac-Hoang
Amat, Alexandre Graell i
Machine Learning
Cryptography and Security
We develop practical and theoretically grounded membership inference attacks (MIAs) against both independent and identically distributed (i.i.d.) data and graph-structured data. Building on the Bayesian decision-theoretic framework of Sablayrolles et al., we derive the Bayes-optimal membership inference rule for node-level MIAs against graph neural networks, addressing key open questions about optimal query strategies in the graph setting. We introduce BASE and G-BASE, tractable approximations of the Bayes-optimal membership inference. G-BASE achieves superior performance compared to previously proposed classifier-based node-level MIA attacks. BASE, which is also applicable to non-graph data, matches or exceeds the performance of prior state-of-the-art MIAs, such as LiRA and RMIA, at a significantly lower computational cost. Finally, we show that BASE and RMIA are equivalent under a specific hyperparameter setting, providing a principled, Bayes-optimal justification for the RMIA attack.
title Practical Bayes-Optimal Membership Inference Attacks
topic Machine Learning
Cryptography and Security
url https://arxiv.org/abs/2505.24089