Towards More Realistic Membership Inference Attacks on Large Diffusion Models

06/22/2023
by   Jan Dubiński, et al.
0

Generative diffusion models, including Stable Diffusion and Midjourney, can generate visually appealing, diverse, and high-resolution images for various applications. These models are trained on billions of internet-sourced images, raising significant concerns about the potential unauthorized use of copyright-protected images. In this paper, we examine whether it is possible to determine if a specific image was used in the training set, a problem known in the cybersecurity community and referred to as a membership inference attack. Our focus is on Stable Diffusion, and we address the challenge of designing a fair evaluation framework to answer this membership question. We propose a methodology to establish a fair evaluation setup and apply it to Stable Diffusion, enabling potential extensions to other generative models. Utilizing this evaluation setup, we execute membership attacks (both known and newly introduced). Our research reveals that previously proposed evaluation setups do not provide a full understanding of the effectiveness of membership inference attacks. We conclude that the membership inference attack remains a significant challenge for large diffusion models (often deployed as black-box systems), indicating that related privacy and copyright issues will persist in the foreseeable future.

READ FULL TEXT

page 12

page 20

research
02/02/2023

Are Diffusion Models Vulnerable to Membership Inference Attacks?

Diffusion-based generative models have shown great potential for image s...
research
01/24/2023

Membership Inference of Diffusion Models

Recent years have witnessed the tremendous success of diffusion models i...
research
03/29/2023

HoloDiffusion: Training a 3D Diffusion Model using 2D Images

Diffusion models have emerged as the best approach for generative modeli...
research
02/07/2023

Membership Inference Attacks against Diffusion Models

Diffusion models have attracted attention in recent years as innovative ...
research
07/07/2023

Scalable Membership Inference Attacks via Quantile Regression

Membership inference attacks are designed to determine, using black box ...
research
08/23/2023

A Probabilistic Fluctuation based Membership Inference Attack for Diffusion Models

Membership Inference Attack (MIA) identifies whether a record exists in ...
research
05/16/2020

DAMIA: Leveraging Domain Adaptation as a Defense against Membership Inference Attacks

Deep Learning (DL) techniques allow ones to train models from a dataset ...

Please sign up or login with your details

Forgot password? Click here to reset