arXiv:2601.12929cs.CVcs.AI2026-01被引 4

通过检测模型激活模式,判断图像是否被用于训练。

Membership Inference Test: Auditing Training Data in Object Classification Models

  • 设计专用MINT架构,利用卷积层捕捉训练时的激活特征。
  • 在17万+图像数据上实现70%-80%的成员推断准确率。
  • 适合关注模型隐私与数据泄露风险的研究者使用。

本研究分析了会员推断测试(MINT)在目标识别领域的性能,旨在判断特定数据是否曾用于模型训练。针对目标识别任务,我们提出了专门设计的MINT模型架构,以优化数据利用效率并应对该领域复杂性。实验在三个公开数据库上进行,涵盖超过17.4万张图像,包括目标检测模型、嵌入提取器和MINT模块。所提架构利用卷积层捕获训练过程中的激活模式,成功识别出训练与测试数据,准确率在70%至80%之间,具体取决于输入MINT模块的检测模块层数。此外,研究还深入分析了影响MINT性能的因素,揭示了提升训练透明度的关键机制。

原文摘要 · Abstract (English)

In this research, we analyze the performance of Membership Inference Tests (MINT), focusing on determining whether given data were utilized during the training phase, specifically in the domain of object recognition. Within the area of object recognition, we propose and develop architectures tailored for MINT models. These architectures aim to optimize performance and efficiency in data utilization, offering a tailored solution to tackle the complexities inherent in the object recognition domain. We conducted experiments involving an object detection model, an embedding extractor, and a MINT module. These experiments were performed in three public databases, totaling over 174K images. The proposed architecture leverages convolutional layers to capture and model the activation patterns present in the data during the training process. Through our analysis, we are able to identify given data used for testing and training, achieving precision rates ranging between 70% and 80%, contingent upon the depth of the detection module layer chosen for input to the MINT module. Additionally, our studies entail an analysis of the factors influencing the MINT Module, delving into the contributing elements behind more transparent training processes.

模型隐私数据泄露目标识别

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。