arXiv ScienceSearch

arXiv · 2609.12367

Membership Inference via Pairwise Likelihood Ratios

Abstract

Membership inference attacks (MIAs) are the standard tool for auditing the privacy risks of machine learning models. Given a query point, an MIA aims to determine whether that point was used to train the target model. In practice, such inference must rely on the statistical signals exposed by the model's outputs, such as confidence scores, logits, and intermediate feature representations. However, existing methods often fail to efficiently summarize and combine these statistical signals. To address this limitation, we propose Pairwise Likelihood MIA (PL-MIA), a unified method that combines a Gaussian likelihood-ratio (GLR) statistic with population calibration and the Cauchy combination test. We characterize theoretically how the GLR retains variance-contraction signals and establish conditions under which population calibration and Cauchy combination improve attack power. We obtain $p$-values from pairwise comparisons between the query point and reference points not used for training, and aggregate these continuous signals using the Cauchy combination test. This preserves the evidence strength that is discarded when each pairwise comparison is reduced to a binary vote. Extensive experiments demonstrate that PL-MIA outperforms strong baselines, improving the true positive rate (TPR) by over 25\% in the critical low-false-positive regime, corroborating our theoretical findings. These results demonstrate how statistical principles can turn noisy model outputs into more powerful, calibrated, and reproducible evidence for membership privacy auditing.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Shengjie Niu, Zebin Yun, Yeheng Ge, Jian Huang. 2026-09-11. Membership Inference via Pairwise Likelihood Ratios. https://arxiv.org/abs/2609.12367

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Combinatorial Inference on the Optimal Assortment in Multinomial Logit Models

Assortment optimization has received active explorations in the past few decades due to its practical importance. Despite the extensive literature dealing with optimization algorithms and latent score estimation, uncertainty quantification for the optimal assortment still needs to be explored and is of great practical significance. Instead of estimating and recovering the complete optimal offer set, decision-makers may only be interested in testing whether a given property holds true for the optimal assortment, such as whether they should include several products of interest in the optimal set, or how many categories of products the optimal set should include. This paper proposes a novel inferential framework for testing such properties. We consider the widely adopted multinomial logit (MNL) model, where we assume that each customer will purchase an item within the offered products with a probability proportional to the underlying preference score associated with the product. We reduce inferring a general optimal assortment property to quantifying the uncertainty associated with the sign change point detection of the marginal revenue gaps. We show the asymptotic normality of the marginal revenue gap estimator, and construct a maximum statistic via the gap estimators to detect the sign change point. By approximating the distribution of the maximum statistic with multiplier bootstrap techniques, we propose a valid testing procedure. We also conduct numerical experiments to assess the performance of our method.

stat.ML

C-Learner: Constrained Learning for Causal Inference

Debiasing methods such as augmented inverse propensity weighting (AIPW), and targeted maximum likelihood estimation (TMLE) enjoy asymptotic properties like semiparametric efficiency and double robustness, but can produce unstable estimates in practice that require ad hoc adjustments (e.g., truncating propensity scores). In contrast, simple plug-ins can remain stable but lack these asymptotic guarantees. To achieve the best of both worlds---a plug-in that enjoys strong asymptotic guarantees---we propose a constrained learning framework that trains a nuisance model to minimize prediction error subject to the constraint that the estimated first-order error of the resulting plug-in is zero. To compare different debiasing methods that share the same classical limit, we study a stylized high-dimensional regression problem where nuisance estimation errors do not vanish asymptotically. Our unified analysis covers both $d n$, as well as ridge regularization, and characterizes how overlap affects the estimators' limiting distributions. Under sufficient overlap, our estimator has smaller asymptotic variance than AIPW and TMLE, whereas when overlap deteriorates so much that AIPW and TMLE are no longer root-$n$ consistent, constrained learning still retains the direct plug-in's root-$n$ limit. Empirically, across a range of experimental settings including those with text-based covariates and language models, we observe our estimator outperforms classical debiasing methods in challenging settings with limited overlap between treatment and control, and performs similarly otherwise.

stat.ML

Small Gradient Norm Regret for Online Convex Optimization

This paper introduces a new problem-dependent regret measure for online convex optimization with smooth losses. The notion, which we call the $G^\star$ regret, depends on the cumulative squared gradient norm evaluated at the decision in hindsight. We show that the $G^\star$ regret strictly refines the existing $L^\star$ (small loss) regret, and that it can be arbitrarily sharper when the losses have vanishing curvature around the hindsight decision. We establish upper and lower bounds on the $G^\star$ regret and extend our results to dynamic regret and bandit settings. As a byproduct, we refine the existing convergence analysis of stochastic optimization algorithms in the interpolation regime. Some experiments validate our theoretical findings.

stat.ML