The pervasive deployment of deep learning models across critical domains has concurrently intensified privacy concerns due to their inherent propensity for data memorization. While Membership Inference Attacks (MIAs) serve as the gold standard for auditing these privacy vulnerabilities, conventional MIA paradigms are increasingly constrained by the prohibitive computational costs of shadow model training and a precipitous performance degradation under low False Positive Rate constraints. To overcome these challenges, we introduce a novel perspective by leveraging the principles of model reprogramming as an active signal amplifier for privacy leakage. Building upon this insight, we present \texttt{ReproMIA}, a unified and efficient proactive framework for membership inference. We rigorously substantiate, both theoretically and empirically, how our methodology proactively induces and magnifies latent privacy footprints embedded within the model's representations. We provide specialized instantiations of \texttt{ReproMIA} across diverse architectural paradigms, including LLMs, Diffusion Models, and Classification Models. Comprehensive experimental evaluations across more than ten benchmarks and a variety of model architectures demonstrate that \texttt{ReproMIA} consistently and substantially outperforms existing state-of-the-art baselines, achieving a transformative leap in performance specifically within low-FPR regimes, such as an average of 5.25\% AUC and 10.68\% TPR@1\%FPR increase over the runner-up for LLMs, as well as 3.70\% and 12.40\% respectively for Diffusion Models.
翻译:深度学习模型在关键领域的广泛部署,因其固有的数据记忆倾向而加剧了隐私担忧。尽管成员推理攻击(MIA)是审计这些隐私漏洞的金标准,但传统的MIA范式正日益受到影子模型训练高昂计算成本及低假阳性率约束下性能急剧下降的限制。为克服这些挑战,我们引入了一种新颖视角,利用模型重编程原理作为隐私泄露的主动信号放大器。基于这一洞见,我们提出了统一且高效的主动推理框架\texttt{ReproMIA}。通过理论与实证双重验证,我们严格论证了该方法如何主动诱发并放大嵌入模型表征中的潜在隐私足迹。我们针对LLM、扩散模型及分类模型等不同架构范式提供了\texttt{ReproMIA}的专门实例化方案。在十余个基准数据集及多种模型架构上的全面实验评估表明,\texttt{ReproMIA}持续且显著优于现有最先进基线,尤其在低FPR场景中实现了变革性性能突破:例如在LLM任务中,AUC和TPR@1%FPR平均较第二名分别提升5.25%和10.68%;在扩散模型中相应提升分别达3.70%和12.40%。