We present the first systematic Membership Inference Attack (MIA) evaluation of LALMs. Using Multi-modal Blind Baselines based on textual, spectral and prosodic features, we demonstrate that common audio datasets exhibit near-perfect train/test separability (AUC ~ 1.0) even without model inference, thus MIA may primarily detect distribution shift. We therefore introduce a blind-baseline protocol to control for this confound. Under this protocol, we identify that the distribution-matched datasets enable reliable MIA evaluation without distribution-shift artifacts. We benchmark multiple MIA methods and conduct modality disentanglement experiments on these datasets. The results reveal that LALM memorization is cross-modal, arising only from binding a speaker's vocal identity with its text. These findings establish a principled standard for auditing LALMs beyond spurious correlations. Our codebase is available at https://github.com/snooow1029/ALM_MIA.
翻译:我们提出了首个对LALMs的系统性成员推理攻击(MIA)评估。通过基于文本、频谱和韵律特征的多模态盲基线方法,我们证明了常见音频数据集即使在无模型推理时也能展现近乎完美的训练/测试可分性(AUC ~ 1.0),因此MIA可能主要检测分布偏移。为此,我们引入了盲基线协议来控制这一混杂因素。在该协议下,我们发现分布匹配的数据集能够实现无分布偏移伪影的可靠MIA评估。我们基准测试了多种MIA方法,并在这些数据集上进行了模态解缠实验。结果表明,LALM的记忆是跨模态的,仅产生于将说话者的声纹身份与文本绑定。这些发现为审计LALMs建立了超越虚假关联的原则性标准。我们的代码库可在https://github.com/snooow1029/ALM_MIA获取。