Blind Baselines Beat Membership Inference Attacks for Foundation Models

June 23, 2024 Β· Declared Dead Β· πŸ› 2025 IEEE Security and Privacy Workshops (SPW)

πŸ‘» CAUSE OF DEATH: Ghosted
No code link whatsoever

"No code URL or promise found in abstract"

Evidence collected by the PWNC Scanner

Authors Debeshee Das, Jie Zhang, Florian Tramèr arXiv ID 2406.16201 Category cs.CR: Cryptography & Security Cross-listed cs.CL, cs.LG Citations 59 Venue 2025 IEEE Security and Privacy Workshops (SPW) Last Checked 5 months ago
Abstract
Membership inference (MI) attacks try to determine if a data sample was used to train a machine learning model. For foundation models trained on unknown Web data, MI attacks are often used to detect copyrighted training materials, measure test set contamination, or audit machine unlearning. Unfortunately, we find that evaluations of MI attacks for foundation models are flawed, because they sample members and non-members from different distributions. For 8 published MI evaluation datasets, we show that blind attacks -- that distinguish the member and non-member distributions without looking at any trained model -- outperform state-of-the-art MI attacks. Existing evaluations thus tell us nothing about membership leakage of a foundation model's training data.
Community shame:
Not yet rated
Community Contributions

Found the code? Know the venue? Think something is wrong? Let us know!

πŸ“œ Similar Papers

In the same crypt β€” Cryptography & Security

Died the same way β€” πŸ‘» Ghosted