Privacy Attacks on Image AutoRegressive Models
Antoni Kowalczuk, Jan Dubinski, Franziska Boenisch, Adam Dziedzic
Abstract
Image AutoRegressive generation has emerged as a new powerful paradigm with image autoregressive models (IARs) matching state-of-the-art diffusion models (DMs) in image quality (FID: 1.48 vs. 1.58) while allowing for a higher generation speed. However, the privacy risks associated with IARs remain unexplored, raising concerns regarding their responsible deployment. To address this gap, we conduct a comprehensive privacy analysis of IARs, comparing their privacy risks to the ones of DMs as reference points. Concretely, we develop a novel membership inference attack (MIA) that achieves a remarkably high success rate in detecting training images (with a True Positive Rate at False Positive Rate = 1% of 86.38% vs. 6.38% for DMs with comparable attacks). We leverage our novel MIA to provide dataset inference (DI) for IARs, and show that it requires as few as 6 samples to detect dataset membership (compared to 200 for DI in DMs), confirming a higher information leakage in IARs. Finally, we are able to extract hundreds of training data points from an IAR (e.g., 698 from VAR-d30). Our results suggest a fundamental privacy-utility trade-off: while IARs excel in image generation quality and speed, they are empirically significantly more vulnerable to privacy attacks compared to DMs that achieve similar performance. We release the code at https://github.com/sprintml/ privacy_attacks_against_iars for reproducibility.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3af9de8d-7f41-4949-9c6c-2aba82b4c04dCited by top-tier papers4
- Data Provenance for Image Auto-Regressive GenerationBihe Zhao, Louis Kerner, Michel Meintz, Tameem Bakr et al.ICLR 2026 · 5 citations
- Natural Identifiers for Privacy and Data Audits in Large Language ModelsLorenzo Rossi, Bartlomiej Marek, Franziska Boenisch, Adam DziedzicICLR 2026 · 3 citations
- Demystifying Foreground-Background Memorization in Diffusion ModelsJimmy Z. Di, Yiwei Lu, Yaoliang Yu, Gautam Kamath et al.AAAI 2026 · 1 citation
- Enhancing Membership Inference Attacks on Diffusion Models from a Frequency-Domain PerspectivePuwei Lian, Yujun Cai, Songze Li, Bingkun BAOICML 2026
Builds on43
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- Denoising Diffusion Implicit ModelsJiaming Song, Chenlin Meng, Stefano ErmonICLR 2021 · 11,743 citations
- Photorealistic Text-to-Image Diffusion Models with Deep Language UnderstandingChitwan Saharia, William Chan, Saurabh Saxena, Lala Li et al.NeurIPS 2022 · 8,965 citations
- Scalable Diffusion Models with TransformersWilliam Peebles, Saining XieICCV 2023 · 5,568 citations
Related papers
- Membership Inference Attacks on Diffusion Models via Quantile RegressionShuai Tang, Steven Wu, Sergül Aydöre, Michael Kearns et al.ICML 2024 · 22 citations
- Black-box Membership Inference Attacks against Fine-tuned Diffusion ModelsYan Pang, Tianhao WangNDSS 2025
- Unveiling Structural Memorization: Structural Membership Inference Attack for Text-to-Image Diffusion ModelsQiao Li, Xiaomeng Fu, Xi Wang, Jin Liu et al.ACM MM 2024 · 6 citations
- Privacy Leaks by Adversaries: Adversarial Iterations for Membership Inference AttackJing Xue, Zhishen Sun, Haishan Ye, Luo Luo et al.AAAI 2026
- ICAS: Detecting Training Data from Autoregressive Image Generative ModelsHongyao Yu, Yixiang Qiu, Yiheng Yang, Hao Fang et al.ACM MM 2025 · 2 citations
