Jul 2026· 2026 3rd World Conference on Computer and Information Security (WCCIS)· pp. 213-216· 0 citations· 5 references
Abstract
Membership inference attacks (MIAs) determine whether a queried record was included in a model's training set, posing a significant privacy risk to deployed machine learning services. Existing black-box attacks often depend on confidence vectors or numerous augmented queries, resulting in high query costs. This paper investigates a query-efficient black-box MIA based on adaptive sparse perturbations, which probes only a small subset of input coordinates and stops querying once sufficient prediction instability is observed. We formalize the attack pipeline under a score-based black-box threat model in which the adversary observes the full output probability vector but does not know model internals, training data, deployed defenses, or hidden preprocessing steps. We further define input coordinates as scalar dimensions of numeric inputs, specify sparse-coordinate sampling and perturbation magnitudes, and calibrate adaptive stopping thresholds on held-out validation data rather than on the final evaluation split. Using archived experimental results, the adaptive high-precision attack achieves the same average AUC as the fixed high-precision baseline (0.7525 vs. 0.7522) while reducing queries by $25.41 {\%}$. Relaxed sparse variants further cut query costs by up to 82.97% with only minor AUC degradation. Taken as an archival reanalysis, the results indicate that sparse local instability is a useful membership signal and that adaptive stopping can substantially reduce attack cost in black-box privacy evaluation.
Membership inference attacks (MIAs) are the standard tool for auditing the privacy risks of machine learning models. Given a query point, an MIA aims to determine whether that point was used to train the target model. In practice, such inference must rely on the statistical signals exposed by the model's outputs, such...
Sheng-Jie Niu, Ze-Bin Yun, Ye-Heng Ge et al.· 0 citations
Membership inference attacks expose whether individual records were used to train a model, yet existing attacks on diffusion models are largely heuristic and can require substantial query budgets. We introduce DIME (Denoiser Ideal Membership Error), a theoretically grounded and query-efficient framework for membership...
This paper presents a systematic framework for membership inference attacks, in which an adversary with only black-box query access to a deployed classifier determines whether a specific individual's record was part of its training set.
Pramod Prakash· International Journal of Int...· 0 citations
FISGuard reduces the ProjRes attack AUC to near the random-guessing level of 0.5 in most settings, while maintaining downstream task performance close to that of the undefended model and introducing only limited computational overhead, thereby achieving a favorable privacy--utility trade-off.
Machine learning explanations reveal model behavior beyond predictions, creating attack surfaces for model confidentiality and data privacy. We systematize 25 studies that exploit explanations for model extraction, membership inference, and model inversion, treating attribute inference as partial inversion. Existing wo...
ProxyDrift is presented, a framework that identifies and measures drift between production traffic and offline evaluation sets, and constructs and refreshes those evaluation sets accordingly; all without access to raw user data.
Michael Levit, Josh Ledgard, Haoyu Dong et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.