Membership Inference Attack
A method for testing whether a specific example was part of a model's training set, typically by exploiting a model's tendency to behave with higher confidence on data it was trained on. The primary available tool for probing whether unlearning worked, though passing a specific test does not prove zero remaining influence.
Defined in 3 GAGE programs, which carry 5 distinct definitions of it. The wording above is taught in AI Data Governance: The Data Chair.
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
A method for testing whether a specific example was part of a model's training set, typically by exploiting a model's tendency to behave with higher confidence on data it was trained on. The primary available tool for probing whether unlearning worked, though passing a specific test does not prove zero remaining influence.
An AI-specific security threat in which an adversary attempts to determine whether a specific individual's data was included in a model's training set, a risk category a PIPIA's threat analysis for an AI system should address alongside conventional data-security threats.
Determining whether a specific individual's data was in a model's training set, potentially exposing sensitive associations.
An attack in which an adversary, given access to a trained model or its outputs and a candidate record, attempts to determine whether that record was part of the model's training data, with better-than-chance accuracy. A key test for whether a generator's output can leak information about specific individuals.
An attack that determines whether a specific record was used to train a model, without necessarily recovering the record's content, typically by exploiting the model's higher confidence or lower loss on data it has seen during training.
Where it is taught
The exact lessons this term appears in. The first 7 topics of every program are free with a free account.
- Privacy and Data Rights in AI Systems · Ethical and Responsible AI and Operational Governance, AI Literacy & Professional Conduct
- Synthetic data: when it protects, when it launders, and how to tell · Feeding the Machines, AI Data Governance: The Data Chair
- Membership inference and extraction: what a model reveals about its training data · Poison, Leaks, and the Adversary, AI Data Governance: The Data Chair
- Machine unlearning: the emerging answer to deleting what a model learned · The Frontier Discipline, AI Data Governance: The Data Chair
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.