SyncAI.news, a Varaisys broadcasting
Calibrating One-Round Membership Inference with Neighbors
FR

Francesco Rita, Jie Zhang, Florian Tram\`er

· 1 min read

ResearcharXiv cs.AI

Calibrating One-Round Membership Inference with Neighbors

arXiv:2609.36331v1 Announce Type: cross Abstract: The state-of-the-art Membership Inference (MI) methods calibrate their signal separately for each example using reference models, auxiliary models trained to exclude the target. This paradigm scales poorly to modern large models, however, whose training is too expensive to replicate. This has motivated one-round settings, where only a single trained model is available; but without reference models the per-example calibration that drives the strongest attacks can no longer be estimated, leaving the membership signal weak. We ask whether neighbors of the target point can recover this calibration without training any additional model. Our key observation is that reference models serve only to reveal how an example behaves under models not trained on it, and that querying the target model on nearby samples yields the same information. We propose two complementary ways to obtain such neighbors, and show that querying them against an early training checkpoint further sharpens the signal. We evaluate across three image classification datasets and three training setups, showing that neighbors yield strong membership signals and competitive attack performance at no additional training cost.

Original source

This story was published by arXiv cs.AI and written by Francesco Rita, Jie Zhang, Florian Tram\`er. SyncAI.news shows a preview; the complete article is on the publisher's site.

Read the full story on arxiv.org

Similar News