[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-84787-en":3,"doc-seo-84787-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},84787,5909877438554,"Maeve","https://ap-avatar.wpscdn.com/avatar/5600025385ad2bf12a7?_k=1778553567797529272",8,"Research & Report","From Multiplicity to Vulnerability: Privacy Amplification Risk from One-Dataset-Multiple-Model Exposure","Privacy risk from the common one-dataset-multiple-model (ODMM) paradigm is systematically overlooked despite widespread use of shared datasets across many task-specific models. This work demonstrates that ODMM access substantially amplifies privacy leakage, introducing a theoretical privacy composition showing leakage grows as more ODMM models are exposed. PRIME is proposed to assess and quantify the resulting membership-inference leakage under black-box access via aggregation and an attack meta-classifier. Experiments across five image/text benchmarks and diverse model architectures show dataset reuse strongly jeopardizes privacy; differential privacy can reduce effectiveness but PRIME still outperforms single-task attacks.","From Multiplicity to Vulnerability: Privacy Amplification Risk from One-Dataset-Multiple-Model Exposure  \nQirui Huang 1 , Na Li2 , Hongsheng Hu3 , Zhi Zhang 1 , Anmin Fu2 , Yansong Gao 1  \n1The University of Western Australia, Australia  \n2Nanjing University of Science and Technology, China  \n3The University of Newcastle, Australia  \narXiv :2607 .05 1 1 1v 1 [ cs .CR] 6 Jul 2026  \nAbstract—To efficiently exploit a valuable data source (e.g., facial or medical images), it is frequently harnessed to fulfill multiple learning objectives (e.g., facial recognition, age estimation, and race classification). Each trained model is then deployed as an independent API service for corresponding inference. However, the privacy risk introduced by this one-dataset-multiple-model (ODMM) paradigm is completely overlooked by the community.  \nFor the first time, this work reveals that the ODMM setting substantially amplifies privacy leakage. We establish a theoretical framework that proves that privacy leakage accumulates as more ODMM models are exposed, a phenomenon we term ODMM privacy composition. Guided by this theoretical foundation, we propose PRIME (Privacy Amplification RIsk from One-Dataset-Multiple-Model Exposure) to systematically assess this risk and quantify the resulting leakage using membership inference attacks (MIAs). Under black-box access to ODMM models, we design an aggregation mechanism that collectively captures carefully identified privacy signals leaked by individual ODMM models, and construct an attack meta-classifier over the aggregated meta-information to infer the membership status of a given sample jointly. Our results provide strong evidence that dataset reuse across ODMM models strikingly jeopardizes privacy, which is consistently evident across five privacy-sensitive image and textual benchmark datasets and diverse model architectures (from ResNet and ViT to Qwen3-1.7B), spanning three domains: facial analysis, medical imaging, and textual attribution analysis. While mitigations such as differential privacy can reduce the effectiveness of PRIME with trade-offs, our attack still consistently outperforms single-task MIAs.  \nI. INTRODUCTION  \nThe rapid advancement of deep learning (DL) has profoundly reshaped diverse domains such as autonomous driving [1], facial recognition [2], and medical diagnosis [3], while the recent emergence of Artificial Intelligence Generated Content (AIGC), ranging from text generation (e.g., ChatGPT [4]) to image synthesis (e.g., Midjourney [5]), has further propelled this transformative wave. For this success, high-quality data has been recognized as a critical factor for improving model performance in addition to scaled model size [6], [7] . However, this remarkable progress is fundamentally underpinned by the availability of massive task-specific datasets, which remain practically challenging to acquire due to prohibitive collection costs and inherent data scarcity.  \nFortunately, a given dataset typically harbors rich information suitable for diverse learning objectives [8], [9], [10] . Consequently, to overcome data scarcity and maximize valuable  \nresource utility, it has become standard practice across both academia and industry to train multiple individual models over the same dataset (e.g., CelebA), with each addressing a specific task (e.g., age estimation, race, gender, and facial expression recognition) . For another instance, Facebook AI Research’s Detectron2 [11] releases multiple independent task-specific vision models in its model zoo, including object detection, instance segmentation, human keypoint estimation, and panoptic segmentation, all trained on the COCO dataset [12] . Overlooked Privacy Problem: Although repurposing the same data source for multiple tasks optimizes resource efficiency, the privacy risks posed by the collective exposure of one-dataset-multiple-model (ODMM) are essentially overlooked and poorly understood, despite the privacy vulnerabilities of ind","cbCaiiVakzmxy64s","https://ap.wps.com/l/cbCaiiVakzmxy64s","pdf",677503,2,1,18,"English","en",105,"# Introduction\n## Overlooked Privacy Problem\n## Membership Inference Attacks\n## Research Questions\n## Our Work","[{\"question\":\"What does the one-dataset-multiple-model (ODMM) paradigm risk in terms of privacy?\",\"answer\":\"It introduces privacy leakage that is amplified when multiple models trained on the same dataset are exposed via inference APIs. The community has overlooked this collective risk despite known vulnerabilities from single models.\"},{\"question\":\"How does the work explain why privacy leakage becomes worse under ODMM exposure?\",\"answer\":\"It provides a theoretical framework proving that privacy leakage accumulates as more ODMM models are exposed, termed ODMM privacy composition.\"},{\"question\":\"What is PRIME, and how does it quantify the privacy amplification risk?\",\"answer\":\"PRIME systematically assesses membership-inference leakage under black-box access by designing an aggregation mechanism to capture privacy signals from individual ODMM models and then training an attack meta-classifier on the aggregated meta-information.\"}]",1784198237,45,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"from-multiplicity-to-vulnerability-privacy-amplification-risk-from-one-dataset-multiple-model-exposure","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/from-multiplicity-to-vulnerability-privacy-amplification-risk-from-one-dataset-multiple-model-exposure/84787/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-22","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What does the one-dataset-multiple-model (ODMM) paradigm risk in terms of privacy?","Question",{"text":75,"@type":76},"It introduces privacy leakage that is amplified when multiple models trained on the same dataset are exposed via inference APIs. The community has overlooked this collective risk despite known vulnerabilities from single models.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the work explain why privacy leakage becomes worse under ODMM exposure?",{"text":80,"@type":76},"It provides a theoretical framework proving that privacy leakage accumulates as more ODMM models are exposed, termed ODMM privacy composition.",{"name":82,"@type":73,"acceptedAnswer":83},"What is PRIME, and how does it quantify the privacy amplification risk?",{"text":84,"@type":76},"PRIME systematically assesses membership-inference leakage under black-box access by designing an aggregation mechanism to capture privacy signals from individual ODMM models and then training an attack meta-classifier on the aggregated meta-information.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]