acceptodds
Under review as a conference paper at ICLR 2027

Amplifying Privacy Attacks on Tabular Foundation Models via a Stolen Surrogate

Abstract

Tabular foundation models (TFMs) achieve state-of-the-art performance on structured data. The fact that these models are usually adapted for their sensitive downstream tasks by in-context learning raises the question of privacy risks. We show that even a query-only adversary can extract a significant amount of private information from the context examples by first stealing a surrogate of the preconditioned model and then running privacy attacks on the copy. Without a single sample from the in-context data distribution, without knowledge of the context size, and without any write access to the context, the adversary sends random queries, adapts a public TFM checkpoint to the answers, and obtains a high-fidelity surrogate. The adversary can then condition on arbitrary contexts and query the surrogate without any restrictions. We show that the surrogate can significantly amplify the risks of standard privacy attacks, including membership inference, attribute inference, and property inference. We analyze our method across various settings, including different datasets, TFM backbones, context sizes, and output formats. We find that the combination of stealing and privacy attacks generalizes over these settings, and that its success grows with task difficulty. Restricting the output to the predicted label is still vulnerable to theft, but prevents privacy attacks on a classification task, whereas private information from regression still leaks. Our anonymous codebase is available at https://anonymous.4open.science/r/tfm-priv-attack-0BFC.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.