Abstract
The widespread deployment of deep learning models across various applications has raised significant concerns regarding data privacy. Membership inference attacks (MIAs), a major privacy threat, aim to determine whether a specific sample is used during model training, thereby posing significant risks to sensitive information. Most existing MIA methods rely on the model’s final state output, overlooking the process by which the model memorizes training samples. To better exploit model memorization for MIAs, we propose a novel attack method called machine unlearning-based membership inference attack (MU-MIA). The proposed method introduces machine unlearning to incrementally reduce the model’s memorization of specific samples, generating a forgetting trajectory for each sample. The forgetting trajectory is composed of temporal variations in different metrics of the sample during machine unlearning. To distinguish member from non-member samples, we design a BiLSTM-based binary classifier with attention, which captures discriminative temporal patterns within each forgetting trajectory. Moreover, the machine unlearning phase of our attack is conducted under a zero-shot setting, which eliminates the need for any real data during the unlearning process, thereby improving the practicality and generalizability of the attack. We evaluate the proposed MIA method across different datasets and model architectures, and the comparative experimental results show that our method outperforms existing baseline attack methods.
| Original language | English |
|---|---|
| Pages (from-to) | 5514-5529 |
| Number of pages | 16 |
| Journal | IEEE Transactions on Information Forensics and Security |
| Volume | 21 |
| DOIs | |
| State | Published - 2026 |
Keywords
- Membership inference attack
- data privacy
- deep learning
- machine unlearning
Fingerprint
Dive into the research topics of 'MU-MIA: Machine Unlearning for Membership Inference Attacks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver