When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Sun, Ruining, Hu, Hongsheng, Luo, Wei, Zhang, Zhaoxi, Zhang, Yanjun, Yuan, Haizhuan, Zhang, Leo Yu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918047360483328
author Sun, Ruining
Hu, Hongsheng
Luo, Wei
Zhang, Zhaoxi
Zhang, Yanjun
Yuan, Haizhuan
Zhang, Leo Yu
author_facet Sun, Ruining
Hu, Hongsheng
Luo, Wei
Zhang, Zhaoxi
Zhang, Yanjun
Yuan, Haizhuan
Zhang, Leo Yu
contents With the rapid advancement of deep learning technology, pre-trained encoder models have demonstrated exceptional feature extraction capabilities, playing a pivotal role in the research and application of deep learning. However, their widespread use has raised significant concerns about the risk of training data privacy leakage. This paper systematically investigates the privacy threats posed by membership inference attacks (MIAs) targeting encoder models, focusing on contrastive learning frameworks. Through experimental analysis, we reveal the significant impact of model architecture complexity on membership privacy leakage: As more advanced encoder frameworks improve feature-extraction performance, they simultaneously exacerbate privacy-leakage risks. Furthermore, this paper proposes a novel membership inference attack method based on the p-norm of feature vectors, termed the Embedding Lp-Norm Likelihood Attack (LpLA). This method infers membership status, by leveraging the statistical distribution characteristics of the p-norm of feature vectors. Experimental results across multiple datasets and model architectures demonstrate that LpLA outperforms existing methods in attack performance and robustness, particularly under limited attack knowledge and query volumes. This study not only uncovers the potential risks of privacy leakage in contrastive learning frameworks, but also provides a practical basis for privacy protection research in encoder models. We hope that this work will draw greater attention to the privacy risks associated with self-supervised learning models and shed light on the importance of a balance between model utility and training data privacy. Our code is publicly available at: https://github.com/SeroneySun/LpLA_code.
format Preprint
id arxiv_https___arxiv_org_abs_2506_05743
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning
Sun, Ruining
Hu, Hongsheng
Luo, Wei
Zhang, Zhaoxi
Zhang, Yanjun
Yuan, Haizhuan
Zhang, Leo Yu
Cryptography and Security
Artificial Intelligence
With the rapid advancement of deep learning technology, pre-trained encoder models have demonstrated exceptional feature extraction capabilities, playing a pivotal role in the research and application of deep learning. However, their widespread use has raised significant concerns about the risk of training data privacy leakage. This paper systematically investigates the privacy threats posed by membership inference attacks (MIAs) targeting encoder models, focusing on contrastive learning frameworks. Through experimental analysis, we reveal the significant impact of model architecture complexity on membership privacy leakage: As more advanced encoder frameworks improve feature-extraction performance, they simultaneously exacerbate privacy-leakage risks. Furthermore, this paper proposes a novel membership inference attack method based on the p-norm of feature vectors, termed the Embedding Lp-Norm Likelihood Attack (LpLA). This method infers membership status, by leveraging the statistical distribution characteristics of the p-norm of feature vectors. Experimental results across multiple datasets and model architectures demonstrate that LpLA outperforms existing methods in attack performance and robustness, particularly under limited attack knowledge and query volumes. This study not only uncovers the potential risks of privacy leakage in contrastive learning frameworks, but also provides a practical basis for privacy protection research in encoder models. We hope that this work will draw greater attention to the privacy risks associated with self-supervised learning models and shed light on the importance of a balance between model utility and training data privacy. Our code is publicly available at: https://github.com/SeroneySun/LpLA_code.
title When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2506.05743