arXiv:2601.11210cs.CRcs.CV2026-01被引 6

首次揭示文本生成视频模型存在隐私泄露风险,可精准识别训练数据成员。

VidLeaks: Membership Inference Attacks Against Text-to-Video Models

  • 设计双信号检测框架,从关键帧空间相似性和时间生成稳定性入手。
  • 在仅查询模式下仍达97.01%准确率,证明模型存在严重隐私漏洞。
  • 适合关注AI生成内容安全与隐私审计的研究者与开发者。

文本到视频(T2V)模型基于海量网络数据训练,引发版权与隐私担忧。会员推理攻击(MIAs)是评估此类风险的有力工具,但现有方法针对静态数据设计,难以捕捉视频生成中的时空复杂性,尤其忽略了关键帧中记忆信号的稀疏性及随机时间动态带来的不稳定性。本文首次系统研究T2V模型的会员推理攻击,提出新框架VidLeaks,通过两种互补信号探测稀疏-时间记忆:1)空间重建保真度(SRF),利用Top-K相似性放大稀疏关键帧中的空间记忆信号;2)时间生成稳定性(TGS),通过多次查询间的语义一致性度量时间泄漏。我们在三种逐步严格的黑盒设置下评估:监督式、参考式与仅查询式。实验在三个代表性T2V模型上显示严重漏洞:VidLeaks在AnimateDiff上达到82.92%的AUC,在InstructVideo上达97.01%,即使在最严格的仅查询设置下仍具高攻击成功率,揭示了现实可被利用的隐私风险。本工作首次提供确凿证据,表明T2V模型通过稀疏与时间记忆泄露大量成员信息,为视频生成系统的审计奠定基础,并推动新型防御技术发展。代码已公开于:https://zenodo.org/records/17972831。

原文摘要 · Abstract (English)

The proliferation of powerful Text-to-Video (T2V) models, trained on massive web-scale datasets, raises urgent concerns about copyright and privacy violations. Membership inference attacks (MIAs) provide a principled tool for auditing such risks, yet existing techniques - designed for static data like images or text - fail to capture the spatio-temporal complexities of video generation. In particular, they overlook the sparsity of memorization signals in keyframes and the instability introduced by stochastic temporal dynamics. In this paper, we conduct the first systematic study of MIAs against T2V models and introduce a novel framework VidLeaks, which probes sparse-temporal memorization through two complementary signals: 1) Spatial Reconstruction Fidelity (SRF), using a Top-K similarity to amplify spatial memorization signals from sparsely memorized keyframes, and 2) Temporal Generative Stability (TGS), which measures semantic consistency across multiple queries to capture temporal leakage. We evaluate VidLeaks under three progressively restrictive black-box settings - supervised, reference-based, and query-only. Experiments on three representative T2V models reveal severe vulnerabilities: VidLeaks achieves AUC of 82.92% on AnimateDiff and 97.01% on InstructVideo even in the strict query-only setting, posing a realistic and exploitable privacy risk. Our work provides the first concrete evidence that T2V models leak substantial membership information through both sparse and temporal memorization, establishing a foundation for auditing video generation systems and motivating the development of new defenses. Code is available at: https://zenodo.org/records/17972831.

隐私安全生成模型会员推理视频生成

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。