arXiv:2603.22987cs.CRcs.LG2026-03综述

重新评估成员推理攻击的隐私威胁,发现其在真实场景下威胁较弱。

A Critical Review on the Effectiveness and Privacy Threats of Membership Inference Attacks

  • 提出评估成员推理攻击威胁的现实条件框架
  • 实证表明在真实条件下攻击效果有限,威胁较弱
  • 适合关注隐私评估与模型实用平衡的研究者

成员推理攻击(MIAs)旨在判断数据样本是否曾用于机器学习(ML)模型的训练,已成为衡量ML隐私泄露的默认标准。本文提出一个评估框架,定义了MIAs构成真正隐私威胁的条件,并基于此回顾代表性攻击。研究发现,在该框架定义的现实条件下,MIAs所代表的隐私威胁较弱。因此,若将MIAs作为隐私度量依赖,可能导致风险过高估计,并因采用过强防御措施而牺牲模型性能。

原文摘要 · Abstract (English)

Membership inference attacks (MIAs) aim to determine whether a data sample was included in a machine learning (ML) model's training set and have become the de facto standard for measuring privacy leakages in ML. We propose an evaluation framework that defines the conditions under which MIAs constitute a genuine privacy threat, and review representative MIAs against it. We find that, under the realistic conditions defined in our framework, MIAs represent weak privacy threats. Thus, relying on them as a privacy metric in ML can lead to an overestimation of risk and to unnecessary sacrifices in model utility as a consequence of employing too strong defenses.

隐私安全成员推理模型评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。