通过扰动扩散过程中的潜在空间,识别音乐生成模型的训练数据。
Membership Inference Attack Against Music Diffusion Models via Generative Manifold Perturbation
- 利用反向扩散路径的几何特性检测训练成员
- 训练样本所在区域的退化成本显著更高
- 适用于版权审计与生成模型安全评估
会员推理攻击(Membership Inference Attacks, MIAs)用于检测特定音频片段是否被用于训练模型,是审计生成式音乐模型版权合规性的关键工具。然而,实践中基于损失的信号(如重建误差)与人类感知对齐度低,导致在法证所需的低误报率(FPR)下分离性能差。本文提出潜稳性对抗探测器(LSA-Probe),一种白盒方法,通过测量反向扩散过程中达到固定感知退化阈值所需的最小时间归一化扰动预算来评估几何属性。我们发现,训练成员位于更稳定的区域,其退化成本显著更高。
原文摘要 · Abstract (English)
Membership inference attacks (MIAs) test whether a specific audio clip was used to train a model, making them a key tool for auditing generative music models for copyright compliance. However, loss-based signals (e.g., reconstruction error) are weakly aligned with human perception in practice, yielding poor separability at the low false-positive rates (FPRs) required for forensics. We propose the Latent Stability Adversarial Probe (LSA-Probe), a white-box method that measures a geometric property of the reverse diffusion: the minimal time-normalized perturbation budget needed to cross a fixed perceptual degradation threshold at an intermediate diffusion state. We show that training members, residing in more stable regions, exhibit a significantly higher degradation cost.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。