Automated Membership Inference Attacks: Discovering MIA Signal Computations using LLM Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Tran, Toan, Kotevska, Olivera, Xiong, Li
Format: Preprint
Published: 2026
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866917354029449216
author Tran, Toan
Kotevska, Olivera
Xiong, Li
author_facet Tran, Toan
Kotevska, Olivera
Xiong, Li
contents Membership inference attacks (MIAs), which enable adversaries to determine whether specific data points were part of a model's training dataset, have emerged as an important framework to understand, assess, and quantify the potential information leakage associated with machine learning systems. Designing effective MIAs is a challenging task that usually requires extensive manual exploration of model behaviors to identify potential vulnerabilities. In this paper, we introduce AutoMIA -- a novel framework that leverages large language model (LLM) agents to automate the design and implementation of new MIA signal computations. By utilizing LLM agents, we can systematically explore a vast space of potential attack strategies, enabling the discovery of novel strategies. Our experiments demonstrate AutoMIA can successfully discover new MIAs that are specifically tailored to user-configured target model and dataset, resulting in improvements of up to 0.18 in absolute AUC over existing MIAs. This work provides the first demonstration that LLM agents can serve as an effective and scalable paradigm for designing and implementing MIAs with SOTA performance, opening up new avenues for future exploration.
format Preprint
id arxiv_https___arxiv_org_abs_2603_19375
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Automated Membership Inference Attacks: Discovering MIA Signal Computations using LLM Agents
Tran, Toan
Kotevska, Olivera
Xiong, Li
Cryptography and Security
Machine Learning
Membership inference attacks (MIAs), which enable adversaries to determine whether specific data points were part of a model's training dataset, have emerged as an important framework to understand, assess, and quantify the potential information leakage associated with machine learning systems. Designing effective MIAs is a challenging task that usually requires extensive manual exploration of model behaviors to identify potential vulnerabilities. In this paper, we introduce AutoMIA -- a novel framework that leverages large language model (LLM) agents to automate the design and implementation of new MIA signal computations. By utilizing LLM agents, we can systematically explore a vast space of potential attack strategies, enabling the discovery of novel strategies. Our experiments demonstrate AutoMIA can successfully discover new MIAs that are specifically tailored to user-configured target model and dataset, resulting in improvements of up to 0.18 in absolute AUC over existing MIAs. This work provides the first demonstration that LLM agents can serve as an effective and scalable paradigm for designing and implementing MIAs with SOTA performance, opening up new avenues for future exploration.
title Automated Membership Inference Attacks: Discovering MIA Signal Computations using LLM Agents
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2603.19375