Training data membership inference via Gaussian process meta-modeling: a post-hoc analysis approach

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Huang, Yongchao, Zhang, Pengfei, Mumtaz, Shahzad
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866915576188764160
author Huang, Yongchao
Zhang, Pengfei
Mumtaz, Shahzad
author_facet Huang, Yongchao
Zhang, Pengfei
Mumtaz, Shahzad
contents Membership inference attacks (MIAs) test whether a data point was part of a model's training set, posing serious privacy risks. Existing methods often depend on shadow models or heavy query access, which limits their practicality. We propose GP-MIA, an efficient and interpretable approach based on Gaussian process (GP) meta-modeling. Using post-hoc metrics such as accuracy, entropy, dataset statistics, and optional sensitivity features (e.g. gradients, NTK measures) from a single trained model, GP-MIA trains a GP classifier to distinguish members from non-members while providing calibrated uncertainty estimates. Experiments on synthetic data, real-world fraud detection data, CIFAR-10, and WikiText-2 show that GP-MIA achieves high accuracy and generalizability, offering a practical alternative to existing MIAs.
format Preprint
id arxiv_https___arxiv_org_abs_2510_21846
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Training data membership inference via Gaussian process meta-modeling: a post-hoc analysis approach
Huang, Yongchao
Zhang, Pengfei
Mumtaz, Shahzad
Machine Learning
Artificial Intelligence
Membership inference attacks (MIAs) test whether a data point was part of a model's training set, posing serious privacy risks. Existing methods often depend on shadow models or heavy query access, which limits their practicality. We propose GP-MIA, an efficient and interpretable approach based on Gaussian process (GP) meta-modeling. Using post-hoc metrics such as accuracy, entropy, dataset statistics, and optional sensitivity features (e.g. gradients, NTK measures) from a single trained model, GP-MIA trains a GP classifier to distinguish members from non-members while providing calibrated uncertainty estimates. Experiments on synthetic data, real-world fraud detection data, CIFAR-10, and WikiText-2 show that GP-MIA achieves high accuracy and generalizability, offering a practical alternative to existing MIAs.
title Training data membership inference via Gaussian process meta-modeling: a post-hoc analysis approach
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2510.21846