Diffusion models pose risks of privacy breaches and copyright disputes, primarily stemming from the potential utilization of unauthorized data during the training phase. The Training Membership Inference (TMI) task aims to determine whether a specific sample has been used in the training process of a target model, representing a critical tool for privacy violation verification. However, the increased stochasticity inherent in diffusion renders traditional shadow-model-based or metric-based methods ineffective when applied to diffusion models. Moreover, existing methods only yield binary classification labels which lack necessary comprehensibility in practical applications. In this paper, we explore a novel perspective for the TMI task by leveraging the intrinsic generative priors within the diffusion model. Compared with unseen samples, training samples exhibit stronger generative priors within the diffusion model, enabling the successful reconstruction of substantially degraded training images. Consequently, we propose the Degrade Restore Compare (DRC) framework. In this framework, an image undergoes sequential degradation and restoration, and its membership is determined by comparing it with the restored counterpart. Experimental results verify that our approach not only significantly outperforms existing methods in terms of accuracy but also provides comprehensible decision criteria, offering evidence for potential privacy violations.
翻译:扩散模型在隐私泄露和版权纠纷方面存在风险,这主要源于训练阶段可能使用了未经授权的数据。训练成员推断(TMI)任务旨在确定特定样本是否被用于目标模型的训练过程,是隐私侵犯验证的关键工具。然而,扩散过程固有的随机性使得传统的基于影子模型或基于度量的方法在应用于扩散模型时效果不佳。此外,现有方法仅能产生二分类标签,缺乏实际应用中必要的可解释性。本文从利用扩散模型内部生成先验的新视角探索TMI任务。与未见样本相比,训练样本在扩散模型中表现出更强的生成先验,能够成功重建大幅退化的训练图像。为此,我们提出退化-恢复-对比(DRC)框架。在该框架中,图像依次经历退化和恢复,并通过与其恢复结果对比来判断其成员身份。实验结果表明,我们的方法不仅在准确性上显著优于现有方法,还能提供可解释的决策标准,为潜在隐私侵犯提供证据。