Leave-one-out Distinguishability in Machine Learning
Jiayuan Ye, Anastasia Borovykh, Soufiane Hayou, Reza Shokri
Abstract
We introduce an analytical framework to quantify the changes in a machine learning algorithm's output distribution following the inclusion of a few data points in its training set, a notion we define as leave-one-out distinguishability (LOOD). This is key to measuring data memorization and information leakage as well as the influence of training data points in machine learning. We illustrate how our method broadens and refines existing empirical measures of memorization and privacy risks associated with training data. We use Gaussian processes to model the randomness of machine learning algorithms, and validate LOOD with extensive empirical analysis of leakage using membership inference attacks. Our analytical framework enables us to investigate the causes of leakage and where the leakage is high. For example, we analyze the influence of activation functions, on data memorization. Additionally, our method allows us to identify queries that disclose the most information about the training data in the leave-one-out setting. We illustrate how optimal queries can be used for accurate reconstruction of training data.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 512016d5-cff7-4c35-b206-c99fa82542eaCited by top-tier papers8
- Evaluations of Machine Learning Privacy Defenses are MisleadingMichael Aerni, Jie Zhang, Florian TramèrCCS 2024 · 12 citations
- Practical Bayes-Optimal Membership Inference AttacksMarcus Lassila, Johan Östman, Khac-Hoang Ngo, Alexandre Graell i AmatNeurIPS 2025 · 7 citations
- SMOTE and Mirrors: Exposing Privacy Leakage from Synthetic Minority OversamplingGeorgi Ganev, MohammadReza Nazari, Rees Davison, Amirhassan Fallah Dizche et al.ICLR 2026 · 6 citations
- Learnability and Privacy Vulnerability are Entangled in a Few Critical WeightsXingli Fang, Jung-Eun KimICLR 2026 · 1 citation
- Cram Less to Fit More: Training Data Pruning Improves Memorization of FactsJiayuan Ye, Vitaly Feldman, Kunal TalwarICML 2026 · 1 citation
Builds on20
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Estimating Training Data Influence by Tracing Gradient DescentGarima Pruthi, Frederick Liu, Satyen Kale, Mukund SundararajanNeurIPS 2020 · 784 citations
- What Neural Networks Memorize and Why: Discovering the Long Tail via Influence EstimationVitaly Feldman, Chiyuan ZhangNeurIPS 2020 · 674 citations
- Auditing Differentially Private Machine Learning: How Private is Private SGD?Matthew Jagielski, Jonathan R. Ullman, Alina OpreaNeurIPS 2020 · 354 citations
Related papers
- Enhanced Membership Inference Attacks against Machine Learning ModelsJiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler et al.CCS 2022 · 150 citations
- Students Parrot Their Teachers: Membership Inference on Model DistillationMatthew Jagielski, Milad Nasr, Katherine Lee, Christopher A. Choquette-Choo et al.NeurIPS 2023 · 53 citations
- SoK: Let the Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine LearningAhmed Salem, Giovanni Cherubin, David Evans, Boris Köpf et al.S&P 2023
- PANORAMIA: Privacy Auditing of Machine Learning Models without RetrainingMishaal Kazmi, Hadrien Lautraite, Alireza Akbari, Qiaoyue Tang et al.NeurIPS 2024 · 26 citations
- The Privacy Onion Effect: Memorization is RelativeNicholas Carlini, Matthew Jagielski, Chiyuan Zhang, Nicolas Papernot et al.NeurIPS 2022 · 175 citations
