On the Difficulty of Membership Inference Attacks
Shahbaz Rezaei, Xin Liu
Abstract
Recent studies propose membership inference (MI) attacks on deep models, where the goal is to infer if a sample has been used in the training process. Despite their apparent success, these studies only report accuracy, precision, and recall of the positive class (member class). Hence, the performance of these attacks have not been clearly reported on negative class (non-member class). In this paper, we show that the way the MI attack performance has been reported is often misleading because they suffer from high false positive rate or false alarm rate (FAR) that has not been reported. FAR shows how often the attack model mislabel non-training samples (non-member) as training (member) ones. The high FAR makes MI attacks fundamentally impractical, which is particularly more significant for tasks such as membership inference where the majority of samples in reality belong to the negative (non-training) class. Moreover, we show that the current MI attack models can only identify the membership of misclassified samples with mediocre accuracy at best, which only constitute a very small portion of training samples.
We analyze several new features that have not been comprehensively explored for membership inference before, including distance to the decision boundary and gradient norms, and conclude that deep models' responses are mostly similar among train and non-train samples. We conduct several experiments on image classification tasks, including MNIST, CIFAR-10, CIFAR-100, and Ima-geNet, using various model architecture, including LeNet, AlexNet, ResNet, etc. We show that the current stateof-the-art MI attacks cannot achieve high accuracy and low FAR at the same time, even when the attacker is given several advantages. The source code is available at https://github.com/shrezaei/MI-Attack. Dataset Cifar-100 Cifar-100 Cifar-100 Model AlexNet ResNet DenseNet Target Model Train Acc. 92.48% 95.80% 99.98% Target Model Test Acc. 43.87% 74.14% 82.83% Attack Acc. 82.62% 79.13% 87.74% Attack Precision 91.90% 87.3% 86.97% Attack Recall 86.92% 87.85% 98.29% Attack F1 89.23% 87.45% 92.26% Attack Bal. Acc. 74.02% 61.70% 66.65% Attack FAR 38.89% 64.45% 65.00%
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8dcb9fef-4c06-4ae4-9e66-ab99261c43ceCited by top-tier papers17
- On the Importance of Difficulty Calibration in Membership Inference AttacksLauren Watson, Chuan Guo, Graham Cormode, Alexandre SablayrollesICLR 2022 · 189 citations
- Privacy for Free: How does Dataset Condensation Help Privacy?Tian Dong, Bo Zhao, Lingjuan LyuICML 2022 · 154 citations
- Bag of Tricks for Training Data Extraction from Language ModelsWeichen Yu, Tianyu Pang, Qian Liu, Chao Du et al.ICML 2023 · 87 citations
- MI: Multi-modal Models Membership InferencePingyi Hu, Zihan Wang, Ruoxi Sun, Hu Wang et al.NeurIPS 2022 · 39 citations
- Attack-Aware Noise Calibration for Differential PrivacyBogdan Kulynych, Juan Felipe Gómez, Georgios Kaissis, Flávio P. Calmon et al.NeurIPS 2024 · 23 citations
Builds on8
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- The Secret Sharer: Evaluating and Testing Unintended Memorization in Neural NetworksNicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos et al.USENIX Security 2019 · 1,386 citations
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang et al.NDSS 2019 · 1,141 citations
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 586 citations
- Machine Learning Models that Remember Too MuchCongzheng Song, Thomas Ristenpart, Vitaly ShmatikovCCS 2017 · 582 citations
Related papers
- Practical Blind Membership Inference Attack via Differential ComparisonsBo Hui, Yuchen Yang, Haolin Yuan, Philippe Burlina et al.NDSS 2021
- Membership Inference Attacks With False Discovery Rate ControlChenxu Zhao, Wei Qian, Aobo Chen, Mengdi HuaiICCV 2025 · 2 citations
- Privacy Leaks by Adversaries: Adversarial Iterations for Membership Inference AttackJing Xue, Zhishen Sun, Haishan Ye, Luo Luo et al.AAAI 2026
- How Does Data Augmentation Affect Privacy in Machine Learning?Da Yu, Huishuai Zhang, Wei Chen, Jian Yin et al.AAAI 2021 · 67 citations
- Imitative Membership Inference AttackYuntao Du, Yuetian Chen, Hanshen Xiao, Bruno Ribeiro et al.USENIX Security 2026
