Practical Bayes-Optimal Membership Inference Attacks
Paper i proceeding, 2025

We develop practical and theoretically grounded membership inference attacks (MIAs) against both independent and identically distributed (i.i.d.) data and graph-structured data. Building on the Bayesian decision-theoretic framework of [1], we derive the Bayes-optimal membership inference rule for node-level MIAs against graph neural networks, addressing key open questions about optimal query strategies in the graph setting. We introduce BASE and G-BASE, tractable approximations of the Bayes-optimal membership inference. G-BASE achieves superior performance compared to previously proposed classifier-based node-level MIA attacks. BASE, which is also applicable to non-graph data, matches or exceeds the performance of prior state-of-the-art MIAs, such as LiRA and RMIA, at a significantly lower computational cost. Finally, we show that BASE and RMIA are equivalent under a specific hyperparameter setting, providing a principled, Bayes-optimal justification for the RMIA attack.

Författare

Marcus Lassila

Chalmers, Elektroteknik, Kommunikation, Antenner och Optiska Nätverk

Johan Östman

AI Sweden

Khac-Hoang Ngo

Linköpings universitet

Alexandre Graell Amat

Chalmers, Elektroteknik, Kommunikation, Antenner och Optiska Nätverk

Advances in Neural Information Processing Systems

10495258 (ISSN)

Vol. 38 38522-38556
9798331338275 (ISBN)

39th Conference on Neural Information Processing Systems, NeurIPS 2025
San Diego, USA,

Teori för Sekretess och Säkerhet inom Praktisk Federerad Inlärning

Vetenskapsrådet (VR) (2023-05065), 2023-12-01 -- 2027-11-30.

Pålitlig och säker kodad kantberäkning

Vetenskapsrådet (VR) (2020-03687), 2021-01-01 -- 2024-12-31.

Ämneskategorier (SSIF 2025)

Datavetenskap (datalogi)

Annan data- och informationsvetenskap

Mer information

Senast uppdaterat

2026-09-08