Pith. sign in

REVIEW 4 cited by

Formalizing and Estimating Distribution Inference Risks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2109.06024 v6 pith:M25WMBBR submitted 2021-09-13 cs.LG cs.AIcs.CR

classification cs.LGcs.AIcs.CR
keywords attacksinferencedistributiontrainingrisksstatisticaldatadefinition
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Distribution inference, sometimes called property inference, infers statistical properties about a training set from access to a model trained on that data. Distribution inference attacks can pose serious risks when models are trained on private data, but are difficult to distinguish from the intrinsic purpose of statistical machine learning -- namely, to produce models that capture statistical properties about a distribution. Motivated by Yeom et al.'s membership inference framework, we propose a formal definition of distribution inference attacks that is general enough to describe a broad class of attacks distinguishing between possible training distributions. We show how our definition captures previous ratio-based property inference attacks as well as new kinds of attack including revealing the average node degree or clustering coefficient of a training graph. To understand distribution inference risks, we introduce a metric that quantifies observed leakage by relating it to the leakage that would occur if samples from the training distribution were provided directly to the adversary. We report on a series of experiments across a range of different distributions using both novel black-box attacks and improved versions of the state-of-the-art white-box attacks. Our results show that inexpensive attacks are often as effective as expensive meta-classifier attacks, and that there are surprising asymmetries in the effectiveness of attacks. Code is available at https://github.com/iamgroot42/FormEstDistRisks

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Struct-Bench: A Benchmark for Differentially Private Structured Text Generation

    cs.CL 2025-09 conditional novelty 7.0 of 10

    Struct-Bench is a Context-Free Grammar based evaluation platform showing that current differentially private synthetic text generators often fail to preserve structure and semantic diversity.

  2. On Linear Representations and Pretraining Data Frequency in Language Models

    cs.CL 2025-04 conditional novelty 6.0 of 10

    Subject-object co-occurrence frequency in pretraining predicts whether a language model forms linear relational representations, and LRE quality can be used to estimate unknown pretraining term frequencies.

  3. SoK: Data Reconstruction Attacks Against Machine Learning Models: Definition, Metrics, and Benchmark

    cs.CR 2025-06 conditional novelty 5.0 of 10

    The authors define data reconstruction attacks and measure them with dataset-level FID, sample-level distance and coverage, and an LLM visual judge, finding reconstruction quality tracks memorization.

  4. Statistic Maximal Leakage

    cs.IT 2024-11 conditional novelty 5.0 of 10

    Statistic maximal leakage is a new prior-independent, secret-specific privacy measure with additive composition and an efficient min-cost flow computation for deterministic mechanisms.

Pith tools