arXiv:2606.31991cs.LGcs.AI2026-06

通过链式再生增强成员信号,提升生成模型隐私攻击效果。

Amplifying Membership Signal Through Chained Regeneration

论文配图:Amplifying Membership Signal Through Chained Regeneration
图 1 · 摘自论文原文
  • 利用多模态链式生成,让输出不断作为输入,放大成员证据。
  • 成员样本在迭代再生中保持更高连贯性且衰减更慢,显著提升检测率。
  • 无需训练影子模型,适用于图像、文本、扩散及音频等多种模型。

大型生成模型容易记忆训练数据,因此样本验证对隐私审计和版权保护至关重要。当前的成员推理攻击(MIA)与数据集推断攻击(DI)通常依赖单次生成,信号弱且跨模态敏感度低。受模型自噬障碍(MAD)启发,我们提出MADreMIA——一种模型无关框架,可增强白盒、灰盒与黑盒下的MIA和DI。该框架不依赖影子模型训练(对大模型常不可行),而是通过迭代轨迹挖掘模型内在信号实现可扩展推断。其核心为跨多样本模态的链式生成:每轮输出作为下一轮输入,从而在低误报率(FPR)下提升成员证据。实验表明,训练数据中的成员样本在迭代再生中表现出显著更高的连贯性与更慢的退化速度。MADreMIA在图像、扩散模型、语言模型等多类模型上均展现更强信号;初步结果还显示其在音频模型上的潜力。

原文摘要 · Abstract (English)

The tendency of large generative models to memorize training data makes sample verification critical for privacy auditing and copyright enforcement. Current membership (MIA) and dataset inference (DI) attacks often rely on one-shot generations, which yield weak signals and limited sensitivity across modalities. Inspired by Model Autophagy Disorder (MAD), we introduce MADreMIA, a model-agnostic framework that enhances white-, gray-, and black-box MIA and DI. Rather than relying on shadow model training -- often infeasible for large generative models -- our framework facilitates scalable inference by leveraging inherent signals through iterative trajectories. This process utilizes chained generations across diverse modalities, where each output serves as the subsequent input, to improve membership evidence at low FPR. We demonstrate that memorized training samples exhibit significantly higher coherence and slower degradation during iterative regeneration than non-member generations. Our results show that MADreMIA provides richer signals across diverse model families and modalities; we present comprehensive evaluations for IARs, diffusion, and language models, alongside preliminary results demonstrating its potential for audio models.

隐私攻击链式生成成员推理多模态

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。