发表机构
George Washington University(乔治·华盛顿大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对生成模型记忆性审计缺乏空假设的问题,提出两种精确置换检验方法,并推荐尺度限制统计量,在MemBench上实现精确认证。
AI 中文摘要
生成模型的记忆性审计将相似度分数与阈值进行比较,没有空假设分布,其支持的结论可能是错误的。根据MemBench的规则,该基准的缓解措施大致将Stable Diffusion的记忆性减半;在错误发现率控制下审计,随机提示扰动下三分之二的认证图像不再被检测到,注意力重缩放下六分之五不再被检测到,嵌入优化下全部不再被检测到。该领域的数据复制检验,依据其自身的空假设读取,标记了二十四个生成器中十个未复制任何内容。我们认为对于记忆性,空假设是难点,并提供了两个空假设。对于整个模型,训练图像和保留图像在其样本条件下是可交换的,重新标记它们是一种置换检验,当保留图像是随机分割时,对任何统计量都是精确的;在该检验下,最近邻偏好仍在二十四个中的七个上触发,而限制在近重复尺度上的计数在零个上触发(McNemar p=0.016)。对于单张图像,自然的空假设两次失败,且可测量:将图像在随机图像中排序在2,365个对照中产生596个错误发现,重采样独立生成使空假设窄三倍。针对匹配对照校准后,审计在5%错误发现率下认证61张MemBench图像中的36张,保留对照在0.01%的校准分割中被认证,在此基准上每张图像两次生成恢复该计数。校准的最大值,读取偶尔而非典型的复制,认证46张。作为尺度限制统计量,我们推荐交集欧拉特征轮廓的小尺度质量,它也计算复制的不同图像数量,并测试两个模型是否复制相同的图像。
英文摘要
Memorization audits of generative models read similarity scores against thresholds, with no null distribution, and the conclusions they support can be wrong. By MemBench's rule, the benchmark's mitigations roughly halve Stable Diffusion's memorization; audited with false-discovery control, two thirds of the certified images are no longer detected under random prompt perturbations, five sixths under attention rescaling, and all of them under embedding optimization. The field's data-copying test, read against its own null, flags ten of twenty-four generators that reproduce nothing. We argue that for memorization the null is the hard part, and supply two. For a whole model, training and held-out images are exchangeable given its samples, and relabelling them is a permutation test, exact for any statistic when the held-out images are a random split; under it, a nearest-neighbour preference still fires on seven of those twenty-four, and a count restricted to the near-duplicate scale on none (McNemar p=0.016). For single images, the natural nulls fail twice, measurably: ranking an image among random images yields 596 false discoveries among 2,365 controls, and resampling independent generations makes the null three times too narrow. Calibrated against matched controls, the audit certifies 36 of 61 MemBench images at 5% false-discovery rate, held-out controls are certified in 0.01% of calibration splits, and on this benchmark two generations per image recover that count. A calibrated maximum, which reads occasional rather than typical copying, certifies 46. As the scale-restricted statistic we recommend the small-scale mass of the Intersection Euler Characteristic Profile, which also counts distinct images copied and tests whether two models copy the same ones.
Comments23 pages, 5 figures. Code and measurement outputs at https://github.com/sushovan4/memorization-audits