[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-122799-en":3,"doc-seo-122799-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},122799,1649267921044,"Ava Thompson","https://us-avatar.wpscdn.com/avatar/1800007509477c92dfb?_k=1782875107921204101",8,"Research & Report","Fundamental Limits of Membership Inference Attacks on Machine Learning Models","Membership inference attacks (MIAs) can determine whether a specific record was included in a model’s training set, creating direct privacy exposure for individuals. This work establishes theoretical guarantees for such attacks on machine learning models at scale. It identifies the statistical quantity governing attack effectiveness, proves high-probability success in nonlinear regression with overfitting learning procedures, and derives bounds in multiple scenarios. Discretizing data is shown to potentially enhance security by improving the quantity’s limitations under a diversity constraint of the data distribution, supported by simulations.","arXiv :2310 . 13786v6 [ stat .ML] 7 Oct 2025  \nFundamental Limits of Membership Inference Attacks on  \nMachine Learning Models  \nEric Aubinais [eric.aubinais@universite-paris-saclay.fr](eric.aubinais@universite-paris-saclay.fr)  \n[Universit](Universit)[e Paris-Saclay](e Paris-Saclay)´ , [CNRS](CNRS),  \nLaboratoire de math´ematiques d’Orsay, 91405, Orsay, France  \nElisabeth Gassiat [elisabeth.gassiat@universite-paris-saclay.fr](elisabeth.gassiat@universite-paris-saclay.fr)  \n[Universit](Universit)[e Paris-Saclay](e Paris-Saclay)´ , [CNRS](CNRS),  \nLaboratoire de math´ematiques d’Orsay, 91405, Orsay, France  \nPablo Piantanida [pablo.piantanida@mila.quebec](pablo.piantanida@mila.quebec)  \n[ILLS - International Laboratory on Learning Systems](ILLS - International Laboratory on Learning Systems), MILA - Quebec AI Institute, Montreal (QC), Canada, CNRS, CentraleSup´elec — Universit´e Paris-Saclay  \nAbstract  \nMembership inference attacks (MIA) can reveal whether a particular data point was part of the training dataset, potentially exposing sensitive information about individuals. This article provides theoretical guarantees by exploring the fundamental statistical limitations associated with MIAs on machine learning models at large. More precisely, we first derive the statistical quantity that governs the effectiveness and success of such attacks. We then theoretically prove that in a non-linear regression setting with overfitting learning procedures, attacks may have a high probability of success. Finally, we investigate several situations for which we provide bounds on this quantity of interest. Interestingly, our findings indicate that discretizing the data might enhance the learning procedure’s security.  \nSpecifically, it is demonstrated to be limited by a constant, which quantifies the diversity of the underlying data distribution. We illustrate those results through simple simulations.  \nKeywords: Membership Inference Attacks, Statistical Limitations, Privacy, Theoretical Performance Bounds, Overfitting, Trustworthy Machine Learning.  \n1 Introduction  \nIn today’s data-driven era, machine learning models are designed to reach higher performance, and the size of new models will then inherently increase, therefore the information stored (or memorized) in the parameters (Hartley and Tsaftaris, 2022; Del Grosso et al. , 2023) . The protection of sensitive information is of paramount importance. Membership Inference Attacks (MIAs) have emerged as a concerning threat, capable of unveiling whether a specific data point was part of the training dataset of a machine learning model (Shokriet al., 2017; Song et al., 2017a; Nasr et al., 2019; Zhu et al., 2019) . Such attacks can potentially compromise individual privacy and security by exposing sensitive information (Carliniet al., 2023b) . Furthermore, the recent publication by Tabassi et al. (2019) from the National Institute of Standards and Technology (NIST) explicitly highlights that a membership inference attack (MIA) which successfully identifies an individual as being part of the dataset  \n©2025 Eric Aubinais, Elisabeth Gassiat and Pablo Piantanida.  \nLicense: CC-BY 4.0, see [https://creativecommons.org/licenses/by/4.0/](https://creativecommons.org/licenses/by/4.0/) .  \nAubinais, Gassiat and Piantanida  \nused to train a target model constitutes a breach of confidentiality. This raises a crucial question: How should we evaluate and certify privacy in machine learning models?  \nTo date, the most comprehensive defense mechanism against privacy attacks is Differential Privacy (DP), a framework initially introduced by Dwork et al. (2006) . DP has shown remarkable adaptability in safeguarding the privacy of machine learning models during training, as demonstrated by the works of Jayaraman and Evans (2019); Hannun et al. (2021) . However, it is worth noting that achieving a high level of privacy through differentially private training often comes at a significant cost to the accuracy of ","cbCaiqWEiSpeu8WN","https://ap.wps.com/l/cbCaiqWEiSpeu8WN","pdf",813092,1,54,"English","en",105,"# Introduction\n## Membership inference attacks and privacy risk\n## Differential privacy as a defense\n## Motivation for theoretical guarantees","[{\"question\":\"What problem do membership inference attacks (MIAs) address?\",\"answer\":\"MIAs attempt to determine whether a particular data point was part of a model’s training dataset, which can reveal sensitive information about individuals.\"},{\"question\":\"How does the article evaluate privacy limitations for learning procedures?\",\"answer\":\"It derives a statistical quantity that governs the effectiveness of MIAs, proves success results in certain nonlinear regression overfitting settings, and provides bounds for related scenarios.\"},{\"question\":\"What learning conditions can make MIAs more likely to succeed?\",\"answer\":\"In a nonlinear regression setting with overfitting learning procedures, the article proves attacks can have high probability of success.\"}]","Fundamental Limits of Membership Inference Attacks on Machine Learning Models | PDF",1785812960,136,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"fundamental-limits-of-membership-inference-attacks-on-machine-learning-models","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/fundamental-limits-of-membership-inference-attacks-on-machine-learning-models/122799/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem do membership inference attacks (MIAs) address?","Question",{"text":75,"@type":76},"MIAs attempt to determine whether a particular data point was part of a model’s training dataset, which can reveal sensitive information about individuals.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the article evaluate privacy limitations for learning procedures?",{"text":80,"@type":76},"It derives a statistical quantity that governs the effectiveness of MIAs, proves success results in certain nonlinear regression overfitting settings, and provides bounds for related scenarios.",{"name":82,"@type":73,"acceptedAnswer":83},"What learning conditions can make MIAs more likely to succeed?",{"text":84,"@type":76},"In a nonlinear regression setting with overfitting learning procedures, the article proves attacks can have high probability of success.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]