USENIX Security2025Top-tier venue
Enhanced Label-Only Membership Inference Attacks with Fewer Queries
Hao Li, Zheng Li, Siyuan Wu, Yutong Ye, Min Zhang, Dengguo Feng, Yang Zhang
Abstract
Machine Learning (ML) models are vulnerable to membership inference attacks (MIAs), where an adversary aims to determine whether a specific sample was part of the model's training data. Traditional MIAs exploit differences in the model's output posteriors, but in more challenging scenarios (label-only scenarios) where only predicted labels are available, existing works directly utilize the shortest distance of samples reaching decision boundaries as membership signals, denoted as the shortestBD. However, they face two key challenges: low distinguishability between members and nonmembers due to sample diversity, and high query requirements stemming from direction diversity. To overcome these limitations, we propose a novel labelonly attack called DHAttack, designed for Higher performance and Higher stealth, focusing on the boundary distance of individual samples to mitigate the effects of sample diversity, and measuring this distance toward a fixed point to minimize query overhead. Empirical results demonstrate that DHAttack consistently outperforms other advanced attack methods. Notably, in some cases, DHAttack achieves more than an order of magnitude improvement over all baselines in terms of TPR @ 0.1% FPR with just 5 to 30 queries. Furthermore, we explore the reasons for DHAttack's success, and then analyze other crucial factors in the attack performance. Finally, we evaluate several defense mechanisms against DHAttack and demonstrate its superiority over all baseline attacks. 1
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 58d2ae37-1339-407c-9186-64f6bbd3f2b3Cited by top-tier papers4
- VidLeaks: Membership Inference Attacks Against Text-to-Video ModelsLi Wang, Wenyu Chen, Ning Yu, Zheng Li et al.USENIX Security 2026 · 2 citations
- Membership Inference Attacks on Tokenizers of Large Language ModelsMeng Tong, Yuntao Du, Kejiang Chen, Weiming Zhang et al.USENIX Security 2026
- SoK: Colluding Adversaries in Machine Learning PipelinesVasisht Duddu, Lipeng He, Asim Waheed, N. AsokanUSENIX Security 2026
- DCMI: A Differential Calibration Membership Inference Attack Against Retrieval-Augmented GenerationXinyu Gao, Xiangtao Meng, Yingkai Dong, Zheng Li et al.CCS 2025
Builds on22
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang et al.NDSS 2019 · 1,141 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- HopSkipJumpAttack: A Query-Efficient Decision-Based AttackJianbo Chen, Michael I. Jordan, Martin J. WainwrightS&P 2020 · 797 citations
Related papers
- You Only Query Once: An Efficient Label-Only Membership Inference AttackYutong Wu, Han Qiu, Shangwei Guo, Jiwei Li et al.ICLR 2024 · 20 citations
- Membership Leakage in Label-Only ExposuresZheng Li, Yang ZhangCCS 2021 · 185 citations
- Chameleon: Increasing Label-Only Membership Leakage with Adaptive PoisoningHarsh Chaudhari, Giorgio Severi, Alina Oprea, Jonathan R. UllmanICLR 2024 · 8 citations
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 628 citations
- OSLO: One-Shot Label-Only Membership Inference AttacksYuefeng Peng, Jaechul Roh, Subhransu Maji, Amir HoumansadrNeurIPS 2024 · 17 citations
