发表机构
The Hong Kong Polytechnic University(香港理工大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对成员推断攻击中统计信号利用不足的问题,提出PL-MIA方法,结合高斯似然比、总体校准与Cauchy组合检验,在低假阳性率下将TPR提升超25%,实现更强隐私审计。
AI 中文摘要
成员推断攻击(MIA)是审计机器学习模型隐私风险的标准工具。给定一个查询点,MIA旨在确定该点是否被用于训练目标模型。在实践中,此类推断必须依赖模型输出所暴露的统计信号,如置信度分数、logits和中间特征表示。然而,现有方法往往无法高效地总结和组合这些统计信号。为解决这一局限,我们提出了成对似然MIA(PL-MIA),一种统一方法,它结合了高斯似然比(GLR)统计量、总体校准和Cauchy组合检验。我们从理论上刻画了GLR如何保留方差收缩信号,并建立了总体校准和Cauchy组合提高攻击力的条件。我们通过查询点与未用于训练参考点之间的成对比较获得$p$值,并使用Cauchy组合检验聚合这些连续信号。这保留了当每次成对比较被简化为二元投票时所丢弃的证据强度。大量实验表明,PL-MIA优于强基线,在关键的低假阳性率机制下将真阳性率(TPR)提高了超过25%,证实了我们的理论发现。这些结果展示了统计原理如何将噪声模型输出转化为更强大、更校准且可复现的成员隐私审计证据。
英文摘要
Membership inference attacks (MIAs) are the standard tool for auditing the privacy risks of machine learning models. Given a query point, an MIA aims to determine whether that point was used to train the target model. In practice, such inference must rely on the statistical signals exposed by the model's outputs, such as confidence scores, logits, and intermediate feature representations. However, existing methods often fail to efficiently summarize and combine these statistical signals. To address this limitation, we propose Pairwise Likelihood MIA (PL-MIA), a unified method that combines a Gaussian likelihood-ratio (GLR) statistic with population calibration and the Cauchy combination test. We characterize theoretically how the GLR retains variance-contraction signals and establish conditions under which population calibration and Cauchy combination improve attack power. We obtain $p$-values from pairwise comparisons between the query point and reference points not used for training, and aggregate these continuous signals using the Cauchy combination test. This preserves the evidence strength that is discarded when each pairwise comparison is reduced to a binary vote. Extensive experiments demonstrate that PL-MIA outperforms strong baselines, improving the true positive rate (TPR) by over 25\% in the critical low-false-positive regime, corroborating our theoretical findings. These results demonstrate how statistical principles can turn noisy model outputs into more powerful, calibrated, and reproducible evidence for membership privacy auditing.
Comments33 pages, 7 figures and 11 tables