TY - GEN
T1 - TuneMIA
T2 - 28th International Conference on Pattern Recognition, ICPR 2026
AU - Azulay, Noam
AU - Habler, Idan
AU - Shabtai, Asaf
AU - Elovici, Yuval
N1 - Publisher Copyright: © The Author(s), under exclusive license to Springer Nature Switzerland AG 2027.
PY - 2027/1/1
Y1 - 2027/1/1
N2 - Although diffusion models are widely used in tasks such as image synthesis and data augmentation, they may raise privacy concerns. Recent studies examining privacy-related risks to diffusion models have mainly focused on membership inference attacks (MIAs), i.e., predicting whether a particular instance is a member of a target model’s training or fine-tuning data. However, most MIAs assume white/gray-box access to the target model or focus on denoising diffusion probabilistic models. Moreover, none of them make use of information that can be inferred when models are fine-tuned on an individual instance; such information can provide evidence as to whether the image is a member of the training set. This paper introduces a novel MIA approach designed for generative models, which we implement in the TuneMIA attack targeted at diffusion models. TuneMIA leverages the fine-tuning process, utilizing memorization in weights and gradients, without the need for direct access to the model. In our evaluation of TuneMIA, performed on two datasets and attack scenarios, TuneMIA outperformed SOTA MIAs on diffusion models in all examined cases, indicating that the fine-tuning process exposes information about the target model that can contribute to an MIA’s success. We also show that TuneMIA can be used to detect whether an entire dataset was used to fine-tune a model, making it useful for data owners who want to identify unauthorized use of their data. The code is publicly available at https://github.com/noamazulay274/TuneMIA.
AB - Although diffusion models are widely used in tasks such as image synthesis and data augmentation, they may raise privacy concerns. Recent studies examining privacy-related risks to diffusion models have mainly focused on membership inference attacks (MIAs), i.e., predicting whether a particular instance is a member of a target model’s training or fine-tuning data. However, most MIAs assume white/gray-box access to the target model or focus on denoising diffusion probabilistic models. Moreover, none of them make use of information that can be inferred when models are fine-tuned on an individual instance; such information can provide evidence as to whether the image is a member of the training set. This paper introduces a novel MIA approach designed for generative models, which we implement in the TuneMIA attack targeted at diffusion models. TuneMIA leverages the fine-tuning process, utilizing memorization in weights and gradients, without the need for direct access to the model. In our evaluation of TuneMIA, performed on two datasets and attack scenarios, TuneMIA outperformed SOTA MIAs on diffusion models in all examined cases, indicating that the fine-tuning process exposes information about the target model that can contribute to an MIA’s success. We also show that TuneMIA can be used to detect whether an entire dataset was used to fine-tune a model, making it useful for data owners who want to identify unauthorized use of their data. The code is publicly available at https://github.com/noamazulay274/TuneMIA.
UR - https://www.scopus.com/pages/publications/105047547570
U2 - 10.1007/978-3-032-31583-0_13
DO - 10.1007/978-3-032-31583-0_13
M3 - Conference contribution
SN - 9783032315823
T3 - Lecture Notes in Computer Science
SP - 183
EP - 197
BT - Pattern Recognition - 28th International Conference, ICPR 2026, Proceedings
A2 - De Marsico, Maria
A2 - Ho, Tin Kam
A2 - Jurie, Frederic
A2 - Liu, Cheng-Lin
A2 - Lopresti, Daniel
A2 - Nyström, Ingela
A2 - Ogier, Jean-Marc
A2 - Ross, Arun
A2 - Wang, Liang
PB - Springer Science and Business Media Deutschland GmbH
Y2 - 17 August 2026 through 22 August 2026
ER -