Leveraging Adversarial Examples to Quantify Membership Information Leakage

The use of personal data for training machine learning systems comes with a\nprivacy threat and measuring the level of privacy of a model is one of the\nmajor challenges in machine learning today. Identifying training data based on\na trained model is a standard way of measuring the privacy risks induced by the\nmodel. We develop a novel approach to address the problem of membership\ninference in pattern recognition models, relying on information provided by\nadversarial examples. The strategy we propose consists of measuring the\nmagnitude of a perturbation necessary to build an adversarial example. Indeed,\nwe argue that this quantity reflects the likelihood of belonging to the\ntraining data. Extensive numerical experiments on multivariate data and an\narray of state-of-the-art target models show that our method performs\ncomparable or even outperforms state-of-the-art strategies, but without\nrequiring any additional training samples.\n

Paper

Similar papers

© 2026 NYSGPT2525 LLC