SplatLeak: Tracing and Reducing Membership Leakage in 3D Gaussian Splatting
Abstract
A 3D Gaussian Splatting (3DGS) asset can be shared without its source photographs. Can its renders reveal which photographs trained it, when neighboring views can reconstruct images that never supervised optimization? We isolate the fidelity gained from a photograph's own supervision using shared-initialization and matched-schedule interventions, even with three synchronized neighboring views already supervising. We audit membership by comparing target errors with those of same-scene references trained without the candidate pool. On eight new test scenes, a photometric log-ratio improves mean normalized partial AUC over 0–1% FPR by 0.1567 relative to PSNR-GAP. We also audit candidates without supplied poses using registered background images and cameras with known candidate intrinsics. Reference-fitted alignment extends this audit across the tested numerical color changes. To reduce source association before release, we distill students from teacher renders. Ordinary distillation retains teacher-source association even without direct supervision from protected photographs. We instead supervise each protected photograph's registered camera using teachers that excluded it. Across four scenes, this lowers the mean per-asset maximum AUC over nine attack configurations from 0.9457 to 0.7364, at a mean held-out PSNR cost of 0.241 dB relative to membership-agnostic distillation. The student retains higher held-out PSNR and SSIM than training on auxiliary photographs alone.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.