Cascading and Proxy Membership Inference Attacks

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Du, Yuntao, Li, Jiacheng, Chen, Yuetian, Zhang, Kaiyuan, Yuan, Zhizhen, Xiao, Hanshen, Ribeiro, Bruno, Li, Ninghui
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866918137162629120
author Du, Yuntao
Li, Jiacheng
Chen, Yuetian
Zhang, Kaiyuan
Yuan, Zhizhen
Xiao, Hanshen
Ribeiro, Bruno
Li, Ninghui
author_facet Du, Yuntao
Li, Jiacheng
Chen, Yuetian
Zhang, Kaiyuan
Yuan, Zhizhen
Xiao, Hanshen
Ribeiro, Bruno
Li, Ninghui
contents A Membership Inference Attack (MIA) assesses how much a trained machine learning model reveals about its training data by determining whether specific query instances were included in the dataset. We classify existing MIAs into adaptive or non-adaptive, depending on whether the adversary is allowed to train shadow models on membership queries. In the adaptive setting, where the adversary can train shadow models after accessing query instances, we highlight the importance of exploiting membership dependencies between instances and propose an attack-agnostic framework called Cascading Membership Inference Attack (CMIA), which incorporates membership dependencies via conditional shadow training to boost membership inference performance. In the non-adaptive setting, where the adversary is restricted to training shadow models before obtaining membership queries, we introduce Proxy Membership Inference Attack (PMIA). PMIA employs a proxy selection strategy that identifies samples with similar behaviors to the query instance and uses their behaviors in shadow models to perform a membership posterior odds test for membership inference. We provide theoretical analyses for both attacks, and extensive experimental results demonstrate that CMIA and PMIA substantially outperform existing MIAs in both settings, particularly in the low false-positive regime, which is crucial for evaluating privacy risks.
format Preprint
id arxiv_https___arxiv_org_abs_2507_21412
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Cascading and Proxy Membership Inference Attacks
Du, Yuntao
Li, Jiacheng
Chen, Yuetian
Zhang, Kaiyuan
Yuan, Zhizhen
Xiao, Hanshen
Ribeiro, Bruno
Li, Ninghui
Cryptography and Security
Machine Learning
A Membership Inference Attack (MIA) assesses how much a trained machine learning model reveals about its training data by determining whether specific query instances were included in the dataset. We classify existing MIAs into adaptive or non-adaptive, depending on whether the adversary is allowed to train shadow models on membership queries. In the adaptive setting, where the adversary can train shadow models after accessing query instances, we highlight the importance of exploiting membership dependencies between instances and propose an attack-agnostic framework called Cascading Membership Inference Attack (CMIA), which incorporates membership dependencies via conditional shadow training to boost membership inference performance. In the non-adaptive setting, where the adversary is restricted to training shadow models before obtaining membership queries, we introduce Proxy Membership Inference Attack (PMIA). PMIA employs a proxy selection strategy that identifies samples with similar behaviors to the query instance and uses their behaviors in shadow models to perform a membership posterior odds test for membership inference. We provide theoretical analyses for both attacks, and extensive experimental results demonstrate that CMIA and PMIA substantially outperform existing MIAs in both settings, particularly in the low false-positive regime, which is crucial for evaluating privacy risks.
title Cascading and Proxy Membership Inference Attacks
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2507.21412