notesum.ai
Published at November 5Membership Inference Attacks against Large Vision-Language Models
cs.CV
cs.AI
cs.CL
cs.CR
cs.LG
Released Date: November 5, 2024
Authors: Zhan Li1, Yongtao Wu1, Yihang Chen1, Francesco Tonin1, Elias Abad Rocamora1, Volkan Cevher1
Aff.: 1LIONS, EPFL

| Metric | VLLM Tuning | LLM Pre-Training | |||||
| 32 | 64 | 32 | 64 | 128 | 256 | ||
| Perplexity∗ | 0.779 | 0.988 | 0.542 | 0.505 | 0.553 | 0.582 | |
| Perplexity/zlib∗ | 0.609 | 0.986 | 0.56 | 0.537 | 0.581 | 0.603 | |
| Perplexity/lowercase∗ | 0.962 | 0.977 | 0.493 | 0.518 | 0.503 | 0.583 | |
| Min_0% Prob∗ | 0.522 | 0.522 | 0.455 | 0.451 | 0.425 | 0.448 | |
| Min_10% Prob∗ | 0.461 | 0.883 | 0.468 | 0.487 | 0.526 | 0.534 | |
| Min_20% Prob∗ | 0.603 | 0.980 | 0.505 | 0.498 | 0.549 | 0.562 | |
| Max_Prob_Gap | 0.461 | 0.545 | 0.574 | 0.544 | 0.565 | 0.629 | |
| ModRényi∗ | 0.809 | 0.979 | 0.557 | 0.500 | 0.536 | 0.567 | |
| 0.808 | 0.993 | 0.544 | 0.503 | 0.546 | 0.567 | ||
| 0.779 | 0.963 | 0.559 | 0.497 | 0.529 | 0.560 | ||
| Rényi () | Max_0% | 0.506 | 0.514 | 0.541 | 0.515 | 0.489 | 0.571 |
| Max_10% | 0.458 | 0.776 | 0.518 | 0.525 | 0.606 | 0.65 | |
| Max_100% | 0.564 | 0.835 | 0.555 | 0.531 | 0.6 | 0.631 | |
| Rényi () | Max_0% | 0.552 | 0.579 | 0.566 | 0.571 | 0.603 | 0.668 |
| Max_10% | 0.566 | 0.809 | 0.553 | 0.541 | 0.623 | 0.65 | |
| Max_100% | 0.554 | 0.750 | 0.544 | 0.523 | 0.588 | 0.621 | |
| Rényi () | Max_0% | 0.589 | 0.625 | 0.594 | 0.606 | 0.659 | 0.657 |
| Max_10% | 0.607 | 0.787 | 0.583 | 0.556 | 0.629 | 0.663 | |
| Max_100% | 0.553 | 0.709 | 0.592 | 0.576 | 0.568 | 0.649 | |
| Rényi () | Max_0% | 0.600 | 0.638 | 0.607 | 0.615 | 0.688 | 0.669 |
| Max_10% | 0.618 | 0.763 | 0.586 | 0.548 | 0.627 | 0.667 | |
| Max_100% | 0.557 | 0.694 | 0.546 | 0.527 | 0.584 | 0.634 | |