In-Context Probing for Membership Inference in Fine-Tuned Language Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Lu, Zhexi, Chi, Hongliang, Baracaldo, Nathalie, Kadhe, Swanand Ravindra, Jeon, Yuseok, Yu, Lei
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866917162278453248
author Lu, Zhexi
Chi, Hongliang
Baracaldo, Nathalie
Kadhe, Swanand Ravindra
Jeon, Yuseok
Yu, Lei
author_facet Lu, Zhexi
Chi, Hongliang
Baracaldo, Nathalie
Kadhe, Swanand Ravindra
Jeon, Yuseok
Yu, Lei
contents Membership inference attacks (MIAs) pose a critical privacy threat to fine-tuned large language models (LLMs), especially when models are adapted to domain-specific tasks using sensitive data. While prior black-box MIA techniques rely on confidence scores or token likelihoods, these signals are often entangled with a sample's intrinsic properties - such as content difficulty or rarity - leading to poor generalization and low signal-to-noise ratios. In this paper, we propose ICP-MIA, a novel MIA framework grounded in the theory of training dynamics, particularly the phenomenon of diminishing returns during optimization. We introduce the Optimization Gap as a fundamental signal of membership: at convergence, member samples exhibit minimal remaining loss-reduction potential, while non-members retain significant potential for further optimization. To estimate this gap in a black-box setting, we propose In-Context Probing (ICP), a training-free method that simulates fine-tuning-like behavior via strategically constructed input contexts. We propose two probing strategies: reference-data-based (using semantically similar public samples) and self-perturbation (via masking or generation). Experiments on three tasks and multiple LLMs show that ICP-MIA significantly outperforms prior black-box MIAs, particularly at low false positive rates. We further analyze how reference data alignment, model type, PEFT configurations, and training schedules affect attack effectiveness. Our findings establish ICP-MIA as a practical and theoretically grounded framework for auditing privacy risks in deployed LLMs.
format Preprint
id arxiv_https___arxiv_org_abs_2512_16292
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle In-Context Probing for Membership Inference in Fine-Tuned Language Models
Lu, Zhexi
Chi, Hongliang
Baracaldo, Nathalie
Kadhe, Swanand Ravindra
Jeon, Yuseok
Yu, Lei
Cryptography and Security
Machine Learning
Membership inference attacks (MIAs) pose a critical privacy threat to fine-tuned large language models (LLMs), especially when models are adapted to domain-specific tasks using sensitive data. While prior black-box MIA techniques rely on confidence scores or token likelihoods, these signals are often entangled with a sample's intrinsic properties - such as content difficulty or rarity - leading to poor generalization and low signal-to-noise ratios. In this paper, we propose ICP-MIA, a novel MIA framework grounded in the theory of training dynamics, particularly the phenomenon of diminishing returns during optimization. We introduce the Optimization Gap as a fundamental signal of membership: at convergence, member samples exhibit minimal remaining loss-reduction potential, while non-members retain significant potential for further optimization. To estimate this gap in a black-box setting, we propose In-Context Probing (ICP), a training-free method that simulates fine-tuning-like behavior via strategically constructed input contexts. We propose two probing strategies: reference-data-based (using semantically similar public samples) and self-perturbation (via masking or generation). Experiments on three tasks and multiple LLMs show that ICP-MIA significantly outperforms prior black-box MIAs, particularly at low false positive rates. We further analyze how reference data alignment, model type, PEFT configurations, and training schedules affect attack effectiveness. Our findings establish ICP-MIA as a practical and theoretically grounded framework for auditing privacy risks in deployed LLMs.
title In-Context Probing for Membership Inference in Fine-Tuned Language Models
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2512.16292