acceptodds
Under review as a conference paper at ICLR 2027

MA-LiRA: Memory-Aware Membership Inference Attacks

Abstract

Membership inference asks whether a candidate example participated in a model's training set and provides an important tool for empirical privacy auditing. Many strong attacks rely on statistics observed only at the final model checkpoint, potentially discarding information contained in how a candidate's behavior evolves during optimization. We introduce MA-LiRA, a checkpoint-aware membership-inference attack that exploits this training history. For each labeled candidate, MA-LiRA constructs a compact five-dimensional representation from its checkpoint-wise loss trajectory, capturing endpoint fit, overall learning progress, local trajectory irregularity, and temporally weighted changes. Each feature is calibrated using candidate-specific member and non-member shadow distributions, and the resulting likelihood-ratio coordinates are combined by a fusion model trained exclusively from shadow-derived pseudo-target examples, without using target membership labels for fitting or threshold selection. We evaluate MA-LiRA on CIFAR-10, CIFAR-100, and SVHN against a broad set of score-based, calibrated, likelihood-ratio, and trajectory-based membership-inference baselines. Across the evaluated datasets, MA-LiRA consistently improves overall membership discrimination and low-false-positive-rate detection under the stated checkpoint-aware access model. These results indicate that training-history information can provide membership evidence beyond that available from a final-checkpoint statistic alone.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.