发现视觉语言模型数据审计存在假阳性,提出真实场景下的评估新基准
Revisiting Data Auditing in Large Vision-Language Models
- 发现现有审计方法因图像分布差异产生误导性结果
- 新基准下原有方法性能仅略高于随机猜测
- 指出微调、文本信息等三种实际可行的审计场景
随着大语言模型兴起,融合视觉编码器与大语言模型的视觉语言模型(VLM)在通用智能体和机器人控制等任务中展现出巨大潜力。然而,这些模型通常基于海量网络爬取图像训练,引发版权与隐私担忧,数据审计愈发重要。成员推理(MI)作为关键审计技术,在开源VLM如LLaVA上已取得良好效果(AUC > 80%)。本文重新审视该进展,发现当前MI基准存在成员与非成员图像的分布偏移,导致捷径线索人为抬高性能。我们提出基于最优传输的量化指标以衡量分布差异,并构建满足独立同分布条件的新基准。在无偏设置下,现有方法表现仅略优于随机,且理论上限分析显示不可约误差仍很高。尽管如此,我们识别出微调、可访问真实文本、集合推理等三类可行审计场景,系统揭示了MI在VLM中的局限与机遇,为可信数据审计提供指导。
原文摘要 · Abstract (English)
With the surge of large language models (LLMs), Large Vision-Language Models (VLMs)--which integrate vision encoders with LLMs for accurate visual grounding--have shown great potential in tasks like generalist agents and robotic control. However, VLMs are typically trained on massive web-scraped images, raising concerns over copyright infringement and privacy violations, and making data auditing increasingly urgent. Membership inference (MI), which determines whether a sample was used in training, has emerged as a key auditing technique, with promising results on open-source VLMs like LLaVA (AUC > 80%). In this work, we revisit these advances and uncover a critical issue: current MI benchmarks suffer from distribution shifts between member and non-member images, introducing shortcut cues that inflate MI performance. We further analyze the nature of these shifts and propose a principled metric based on optimal transport to quantify the distribution discrepancy. To evaluate MI in realistic settings, we construct new benchmarks with i.i.d. member and non-member images. Existing MI methods fail under these unbiased conditions, performing only marginally better than chance. Further, we explore the theoretical upper bound of MI by probing the Bayes Optimality within the VLM's embedding space and find the irreducible error rate remains high. Despite this pessimistic outlook, we analyze why MI for VLMs is particularly challenging and identify three practical scenarios--fine-tuning, access to ground-truth texts, and set-based inference--where auditing becomes feasible. Our study presents a systematic view of the limits and opportunities of MI for VLMs, providing guidance for future efforts in trustworthy data auditing.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。