arXiv:2506.14919cs.CVcs.LG2025-06被引 6

针对医疗图像扩散模型,提出频段校准的成员推断攻击方法。

Frequency-Calibrated Membership Inference Attacks on Medical Image Diffusion Models

  • 聚焦中频重建误差,避开难重构的高频和低信息量低频
  • 在多个医疗数据集上超越现有攻击方法,准确率显著提升
  • 适合关注医疗数据隐私泄露风险的研究者与防护设计者

扩散模型在医疗图像生成中的应用日益广泛,但也引发隐私担忧。成员推断攻击(MIA)可判断某图像是否用于训练模型,从而量化隐私风险。现有方法依赖扩散重建误差,认为成员图像的误差更低,但医疗图像存在固有难度差异,且扩散模型难以重建高频细节。为此,本文提出频率校准重建误差(FCRE)方法:通过分析逆扩散过程,仅关注中频范围内的重建误差,排除高频(难重构)与低频(信息少)区域,降低图像固有难度带来的干扰。具体计算中频重建误差,并比较重构图像与原图的结构相似性指数(SSIM)。通过阈值判断成员身份。实验在多个医疗图像数据集上验证,该方法性能优于现有MIA方法。

原文摘要 · Abstract (English)

The increasing use of diffusion models for image generation, especially in sensitive areas like medical imaging, has raised significant privacy concerns. Membership Inference Attack (MIA) has emerged as a potential approach to determine if a specific image was used to train a diffusion model, thus quantifying privacy risks. Existing MIA methods often rely on diffusion reconstruction errors, where member images are expected to have lower reconstruction errors than non-member images. However, applying these methods directly to medical images faces challenges. Reconstruction error is influenced by inherent image difficulty, and diffusion models struggle with high-frequency detail reconstruction. To address these issues, we propose a Frequency-Calibrated Reconstruction Error (FCRE) method for MIAs on medical image diffusion models. By focusing on reconstruction errors within a specific mid-frequency range and excluding both high-frequency (difficult to reconstruct) and low-frequency (less informative) regions, our frequency-selective approach mitigates the confounding factor of inherent image difficulty. Specifically, we analyze the reverse diffusion process, obtain the mid-frequency reconstruction error, and compute the structural similarity index score between the reconstructed and original images. Membership is determined by comparing this score to a threshold. Experiments on several medical image datasets demonstrate that our FCRE method outperforms existing MIA methods.

成员推断医疗图像扩散模型隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。