arXiv:2512.02786cs.LG2025-12Conference of the …被引 3

提出跨模态成员推断框架FiMMIA,精准识别多模态模型训练数据

FiMMIA: scaling semantic perturbation-based membership inference across modalities

  • 基于输入扰动分析模型行为差异,捕捉成员与非成员分布特征
  • 在多个微调多模态模型上验证攻击有效,实现高精度成员推断
  • 开源可复现框架,适用于安全评估与数据泄露检测场景

成员推断攻击(MIA)旨在判断特定数据点是否被包含在目标模型的训练集中。尽管已有大量方法用于检测大语言模型中的数据污染,但在多模态大语言模型(MLLMs)上的表现不佳,主要源于多模态组件适配带来的不稳定性及多输入间的分布偏移。本文研究多模态成员推断,解决两个问题:一是识别现有数据集中的分布偏移,二是发布一个扩展基线管道以检测此类偏移。我们还将基于扰动的成员推断方法推广至MLLMs,提出FiMMIA——一个模块化的多模态成员推断框架。该方法训练神经网络分析目标模型对扰动输入的响应,捕捉成员与非成员间的分布差异。在多个微调的多模态模型上的全面评估表明,该扰动式成员推断攻击在多模态领域具有显著有效性。

原文摘要 · Abstract (English)

Membership Inference Attacks (MIAs) aim to determine whether a specific data point was included in the training set of a target model. Although there are have been numerous methods developed for detecting data contamination in large language models (LLMs), their performance on multimodal LLMs (MLLMs) falls short due to the instabilities introduced through multimodal component adaptation and possible distribution shifts across multiple inputs. In this work, we investigate multimodal membership inference and address two issues: first, by identifying distribution shifts in the existing datasets, and second, by releasing an extended baseline pipeline to detect them. We also generalize the perturbation-based membership inference methods to MLLMs and release \textbf{FiMMIA} -- a modular \textbf{F}ramework for \textbf{M}ultimodal \textbf{MIA}.\footnote{The source code and framework have been made publicly available under the MIT license via \href{https://github.com/ai-forever/data_leakage_detect}{link}.The video demonstration is available on \href{https://youtu.be/a9L4-H80aSg}{YouTube}.} Our approach trains a neural network to analyze the target model's behavior on perturbed inputs, capturing distributional differences between members and non-members. Comprehensive evaluations on various fine-tuned multimodal models demonstrate the effectiveness of our perturbation-based membership inference attacks in multimodal domains.

成员推断多模态安全检测数据泄露

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。