通过噪声聚合分析,用低强度噪声注入提升扩散模型成员推理效率与精度。
Noise Aggregation Analysis Driven by Small-Noise Injection: Efficient Membership Inference for Diffusion Models
- 基于噪声聚合分析设计新攻击方法,利用扩散过程中的噪声一致性特征。
- 仅需单次低强度噪声注入,显著放大成员与非成员样本差异。
- 大幅降低查询次数,适合高效评估扩散模型隐私风险的场景。
扩散模型在生成高质量图像方面表现出强大能力,典型代表如Stable Diffusion。然而其广泛应用也带来潜在隐私风险,尤其是成员推理攻击——判断特定数据样本是否曾用于模型训练。现有针对扩散模型的成员推理攻击或直接利用样本损失差异,或依赖图像级重构差异,但普遍忽视了扩散过程中噪声预测的一致性特征,导致推理准确率低或计算成本高。为此,本文提出一种基于噪声聚合分析的成员推理方法,并引入单步、低强度噪声注入策略,以放大成员与非成员样本间的差异。该方法显著减少模型查询需求,实现更高效、更精确的成员推理。
原文摘要 · Abstract (English)
Diffusion models have demonstrated powerful performance in generating high-quality images. A typical example is text-to-image generator like Stable Diffusion. However, their widespread use also poses potential privacy risks. A key concern is membership inference attacks, which attempt to determine whether a particular data sample was used in the model training process. Existing membership inference attacks against diffusion models either directly exploit sample loss differences or rely on image-level reconstruction differences. Both approaches commonly ignore the consistency characteristics of noise prediction during the diffusion process, resulting in either low inference accuracy or high computational costs. To address these shortcomings, we propose a membership inference method based on noise aggregation analysis, and introduce a single-step, low-intensity noise injection diffusion strategy to amplify differences between member and non-member samples. Our proposed approach substantially reduces model query requirements while delivering more efficient and accurate membership inference.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。