Membership Inference Attack Against Music Diffusion Models via Generative Manifold Perturbation

Fuente: arXiv
Guardado en:
Detalles Bibliográficos
Autores principales: Liu, Yuxuan, Zhang, Peihong, Sang, Rui, Li, Zhixin, Tan, Yizhou, Cai, Yiqiang, Li, Shengchen
Formato: Preprint
Publicado: 2026
Materias:
Acceso en línea:
Etiquetas: Agregar Etiqueta
Sin Etiquetas, Sea el primero en etiquetar este registro!
_version_ 1866908804845666304
author Liu, Yuxuan
Zhang, Peihong
Sang, Rui
Li, Zhixin
Tan, Yizhou
Cai, Yiqiang
Li, Shengchen
author_facet Liu, Yuxuan
Zhang, Peihong
Sang, Rui
Li, Zhixin
Tan, Yizhou
Cai, Yiqiang
Li, Shengchen
contents Membership inference attacks (MIAs) test whether a specific audio clip was used to train a model, making them a key tool for auditing generative music models for copyright compliance. However, loss-based signals (e.g., reconstruction error) are weakly aligned with human perception in practice, yielding poor separability at the low false-positive rates (FPRs) required for forensics. We propose the Latent Stability Adversarial Probe (LSA-Probe), a white-box method that measures a geometric property of the reverse diffusion: the minimal time-normalized perturbation budget needed to cross a fixed perceptual degradation threshold at an intermediate diffusion state. We show that training members, residing in more stable regions, exhibit a significantly higher degradation cost.
format Preprint
id arxiv_https___arxiv_org_abs_2602_01645
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Membership Inference Attack Against Music Diffusion Models via Generative Manifold Perturbation
Liu, Yuxuan
Zhang, Peihong
Sang, Rui
Li, Zhixin
Tan, Yizhou
Cai, Yiqiang
Li, Shengchen
Sound
Membership inference attacks (MIAs) test whether a specific audio clip was used to train a model, making them a key tool for auditing generative music models for copyright compliance. However, loss-based signals (e.g., reconstruction error) are weakly aligned with human perception in practice, yielding poor separability at the low false-positive rates (FPRs) required for forensics. We propose the Latent Stability Adversarial Probe (LSA-Probe), a white-box method that measures a geometric property of the reverse diffusion: the minimal time-normalized perturbation budget needed to cross a fixed perceptual degradation threshold at an intermediate diffusion state. We show that training members, residing in more stable regions, exhibit a significantly higher degradation cost.
title Membership Inference Attack Against Music Diffusion Models via Generative Manifold Perturbation
topic Sound
url https://arxiv.org/abs/2602.01645