Effective Code Membership Inference for Code Completion Models via Adversarial Prompts

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Jiang, Yuan, Li, Zehao, Huang, Shan, Treude, Christoph, Su, Xiaohong, Wang, Tiantian
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918209185120256
author Jiang, Yuan
Li, Zehao
Huang, Shan
Treude, Christoph
Su, Xiaohong
Wang, Tiantian
author_facet Jiang, Yuan
Li, Zehao
Huang, Shan
Treude, Christoph
Su, Xiaohong
Wang, Tiantian
contents Membership inference attacks (MIAs) on code completion models offer an effective way to assess privacy risks by inferring whether a given code snippet was part of the training data. Existing black- and gray-box MIAs rely on expensive surrogate models or manually crafted heuristic rules, which limit their ability to capture the nuanced memorization patterns exhibited by over-parameterized code language models. To address these challenges, we propose AdvPrompt-MIA, a method specifically designed for code completion models, combining code-specific adversarial perturbations with deep learning. The core novelty of our method lies in designing a series of adversarial prompts that induce variations in the victim code model's output. By comparing these outputs with the ground-truth completion, we construct feature vectors to train a classifier that automatically distinguishes member from non-member samples. This design allows our method to capture richer memorization patterns and accurately infer training set membership. We conduct comprehensive evaluations on widely adopted models, such as Code Llama 7B, over the APPS and HumanEval benchmarks. The results show that our approach consistently outperforms state-of-the-art baselines, with AUC gains of up to 102%. In addition, our method exhibits strong transferability across different models and datasets, underscoring its practical utility and generalizability.
format Preprint
id arxiv_https___arxiv_org_abs_2511_15107
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Effective Code Membership Inference for Code Completion Models via Adversarial Prompts
Jiang, Yuan
Li, Zehao
Huang, Shan
Treude, Christoph
Su, Xiaohong
Wang, Tiantian
Software Engineering
Artificial Intelligence
Membership inference attacks (MIAs) on code completion models offer an effective way to assess privacy risks by inferring whether a given code snippet was part of the training data. Existing black- and gray-box MIAs rely on expensive surrogate models or manually crafted heuristic rules, which limit their ability to capture the nuanced memorization patterns exhibited by over-parameterized code language models. To address these challenges, we propose AdvPrompt-MIA, a method specifically designed for code completion models, combining code-specific adversarial perturbations with deep learning. The core novelty of our method lies in designing a series of adversarial prompts that induce variations in the victim code model's output. By comparing these outputs with the ground-truth completion, we construct feature vectors to train a classifier that automatically distinguishes member from non-member samples. This design allows our method to capture richer memorization patterns and accurately infer training set membership. We conduct comprehensive evaluations on widely adopted models, such as Code Llama 7B, over the APPS and HumanEval benchmarks. The results show that our approach consistently outperforms state-of-the-art baselines, with AUC gains of up to 102%. In addition, our method exhibits strong transferability across different models and datasets, underscoring its practical utility and generalizability.
title Effective Code Membership Inference for Code Completion Models via Adversarial Prompts
topic Software Engineering
Artificial Intelligence
url https://arxiv.org/abs/2511.15107