FERMI: Exploiting Relations for Membership Inference Against Tabular Diffusion Models

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Mahyar, Abtin, Shafieinejad, Masoumeh, Liu, Yuhan, He, Xi
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916003762405376
author Mahyar, Abtin
Shafieinejad, Masoumeh
Liu, Yuhan
He, Xi
author_facet Mahyar, Abtin
Shafieinejad, Masoumeh
Liu, Yuhan
He, Xi
contents Diffusion models are the leading approach for tabular data synthesis and are increasingly used to share sensitive records. Whether they actually protect privacy has become a pressing question. Membership inference attacks are the standard tool for this purpose, yet existing attacks assume a single-table setting and ignore the multi-relational structure of real sensitive data. A core challenge in assessing privacy risks from membership inference attacks in multi-table settings is how to leverage auxiliary information from relations associated with the target table, such as its parent tables. Particularly, we study a practical setting in which such auxiliary information is available only when training the attack model. At inference time, the attacker observes only the attribute values of the target record from the target table. We propose FERMI (FEature-mapping for Relational Membership Inference), which resolves this gap by enriching single-table features with relational membership signal. Across three tabular diffusion architectures and three real-world relational datasets, FERMI consistently improves attack performance over single-table baselines, with TPR@$0.1$FPR rising by up to 53% over the single-table baseline in the white-box setting and 22% in the black-box setting.
format Preprint
id arxiv_https___arxiv_org_abs_2605_11527
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle FERMI: Exploiting Relations for Membership Inference Against Tabular Diffusion Models
Mahyar, Abtin
Shafieinejad, Masoumeh
Liu, Yuhan
He, Xi
Machine Learning
Cryptography and Security
Databases
Diffusion models are the leading approach for tabular data synthesis and are increasingly used to share sensitive records. Whether they actually protect privacy has become a pressing question. Membership inference attacks are the standard tool for this purpose, yet existing attacks assume a single-table setting and ignore the multi-relational structure of real sensitive data. A core challenge in assessing privacy risks from membership inference attacks in multi-table settings is how to leverage auxiliary information from relations associated with the target table, such as its parent tables. Particularly, we study a practical setting in which such auxiliary information is available only when training the attack model. At inference time, the attacker observes only the attribute values of the target record from the target table. We propose FERMI (FEature-mapping for Relational Membership Inference), which resolves this gap by enriching single-table features with relational membership signal. Across three tabular diffusion architectures and three real-world relational datasets, FERMI consistently improves attack performance over single-table baselines, with TPR@$0.1$FPR rising by up to 53% over the single-table baseline in the white-box setting and 22% in the black-box setting.
title FERMI: Exploiting Relations for Membership Inference Against Tabular Diffusion Models
topic Machine Learning
Cryptography and Security
Databases
url https://arxiv.org/abs/2605.11527