Membership Inference Attacks on Diffusion Models via Quantile Regression
Shuai Tang, Steven Wu, Sergül Aydöre, Michael Kearns, Aaron Roth
摘要
Recently, diffusion models have become popular tools for image synthesis because of their high-quality outputs. However, like other large-scale models, they may leak private information about their training data. Here, we demonstrate a privacy vulnerability of diffusion models through a membership inference (MI) attack, which aims to identify whether a target example belongs to the training set when given the trained diffusion model. Our proposed MI attack learns quantile regression models that predict (a quantile of) the distribution of reconstruction loss on examples not used in training. This allows us to define a granular hypothesis test for determining the membership of a point in the training set, based on thresholding the reconstruction loss of that point using a custom threshold tailored to the example. We also provide a simple bootstrap technique that takes a majority membership prediction over a bag of weak attackers'' which improves the accuracy over individual quantile regression models. We show that our attack outperforms the prior state-of-the-art attack while being substantially less computationally expensive -- prior attacks required training multiple shadow models'' with the same architecture as the model under attack, whereas our attack requires training only much smaller models.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper8
- Membership Inference Attacks Against Fine-tuned Diffusion Language ModelsYuetian Chen, Kaiyuan Zhang, Yuntao Du, Edoardo Stoppa 等ICLR 2026 · 被引用 6 次
- How does Bayesian Sampling help Membership Inference Attacks?Zhenlong Liu, Wenyu Jiang, Feng Zhou, Hongxin WeiICML 2026 · 被引用 3 次
- Order of Magnitude Speedups for LLM Membership InferenceRongting Zhang, Martin Bertran Lopez, Aaron RothEMNLP 2024 · 被引用 1 次
- Tracing the Roots: Leveraging Temporal Dynamics in Diffusion Trajectories for Origin AttributionAndreas Floros, Seyed-Mohsen Moosavi-Dezfooli, Pier Luigi DragottiNeurIPS 2025 · 被引用 1 次
- Towards Black-Box Membership Inference Attack for Diffusion ModelsJingwei Li, Jing Dong, Tianxing He, Jingzhao ZhangICML 2025
它引用的顶会 Paper12
- Denoising Diffusion Probabilistic ModelsJonathan Ho, Ajay Jain, Pieter AbbeelNeurIPS 2020 · 被引用 35,902 次
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Extracting Training Data from Large Language ModelsNicholas Carlini, Florian Tramèr, Eric Wallace, Matthew Jagielski 等USENIX Security 2021 · 被引用 2,866 次
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song 等S&P 2022 · 被引用 1,049 次
- Evaluating Differentially Private Machine Learning in PracticeBargav Jayaraman, David EvansUSENIX Security 2019 · 被引用 586 次
相关 Paper
- Scalable Membership Inference Attacks via Quantile RegressionMartin Bertran Lopez, Shuai Tang, Aaron Roth, Michael Kearns 等NeurIPS 2023 · 被引用 96 次
- Unveiling Structural Memorization: Structural Membership Inference Attack for Text-to-Image Diffusion ModelsQiao Li, Xiaomeng Fu, Xi Wang, Jin Liu 等ACM MM 2024 · 被引用 6 次
- Are Diffusion Models Vulnerable to Membership Inference Attacks?Jinhao Duan, Fei Kong, Shiqi Wang, Xiaoshuang Shi 等ICML 2023 · 被引用 170 次
- Black-box Membership Inference Attacks against Fine-tuned Diffusion ModelsYan Pang, Tianhao WangNDSS 2025
- Privacy Attacks on Image AutoRegressive ModelsAntoni Kowalczuk, Jan Dubinski, Franziska Boenisch, Adam DziedzicICML 2025
