Skip to main content

Membership Inference Attack

A method for testing whether a specific example was part of a model's training set, typically by exploiting a model's tendency to behave with higher confidence on data it was trained on. The primary available tool for probing whether unlearning worked, though passing a specific test does not prove zero remaining influence.

Defined in 3 GAGE programs, which carry 5 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.

How each discipline defines it

The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.

AI Data Governance: The Data Chair

A method for testing whether a specific example was part of a model's training set, typically by exploiting a model's tendency to behave with higher confidence on data it was trained on. The primary available tool for probing whether unlearning worked, though passing a specific test does not prove zero remaining influence.

Certified China AI Regulatory Professional (CCARP)

An AI-specific security threat in which an adversary attempts to determine whether a specific individual's data was included in a model's training set, a risk category a PIPIA's threat analysis for an AI system should address alongside conventional data-security threats.

AI Literacy & Professional Conduct

Determining whether a specific individual's data was in a model's training set, potentially exposing sensitive associations.

AI Data Governance: The Data Chair

An attack in which an adversary, given access to a trained model or its outputs and a candidate record, attempts to determine whether that record was part of the model's training data, with better-than-chance accuracy. A key test for whether a generator's output can leak information about specific individuals.

AI Data Governance: The Data Chair

An attack that determines whether a specific record was used to train a model, without necessarily recovering the record's content, typically by exploiting the model's higher confidence or lower loss on data it has seen during training.

Where it is taught

The exact lessons this term appears in. The first 7 topics of every program are free with a free account.

Terms it appears with

Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.