Membership Inference Attacks and Differential Privacy: a study within the context of Generative Models

Published in IEEE Open Journal of the Computer Society, 2025

Membership attacks pose a major issue in terms of secure machine learning, especially in cases in which real data are sensitive. Models tend to be overconfident in predicting labels from the training set. Nevertheless, its application has traditionally been limited to supervised models, while in the case of generative models we have found that there is a lack of theoretical foundations to bring this concept into the scene. Hence, this article provides the theoretical background in the context of membership inference attacks and their relationship to generative models, including the derivation of an evaluation metric. In addition, the link between these types of attack and differential privacy is shown to be a particular case. Lastly, we empirically show through simulations the intuition and application of the concepts derived.

Recommended citation: Galende, B. A., Apellániz, P. A., Parras, J., Zazo, S., & Uribe, S. (2025). Membership Inference Attacks and Differential Privacy: a study within the context of Generative Models. IEEE Open Journal of the Computer Society. /files/2025-05-21-memebership-inference.pdf

Direct Link