{"id":"https://openalex.org/W7127641312","doi":"https://doi.org/10.48550/arxiv.2602.02819","title":"Membership Inference Attacks from Causal Principles","display_name":"Membership Inference Attacks from Causal Principles","publication_year":2026,"publication_date":"2026-02-02","ids":{"openalex":"https://openalex.org/W7127641312","doi":"https://doi.org/10.48550/arxiv.2602.02819"},"language":null,"primary_location":{"id":"pmh:doi:10.48550/arxiv.2602.02819","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":null,"any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5125048192","display_name":"Mathieu Even","orcid":null},"institutions":[],"countries":[],"is_corresponding":true,"raw_author_name":"Even, Mathieu","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5125059089","display_name":"Cl\u00e9ment Berenfeld","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Berenfeld, Cl\u00e9ment","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5125095463","display_name":"Linus Bleistein","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bleistein, Linus","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5068633454","display_name":"Tudor Cebere","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cebere, Tudor","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5125013160","display_name":"Julie Josse","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Josse, Julie","raw_affiliation_strings":[],"affiliations":[]},{"author_position":"last","author":{"id":null,"display_name":"Bellet, Aur\u00e9lien","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Bellet, Aur\u00e9lien","raw_affiliation_strings":[],"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5125048192"],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.7949000000953674,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.7949000000953674,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.04560000076889992,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11273","display_name":"Advanced Graph Neural Networks","score":0.0142000000923872,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/causal-inference","display_name":"Causal inference","score":0.5936999917030334},{"id":"https://openalex.org/keywords/consistency","display_name":"Consistency (knowledge bases)","score":0.5794000029563904},{"id":"https://openalex.org/keywords/estimator","display_name":"Estimator","score":0.560699999332428},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.5472999811172485},{"id":"https://openalex.org/keywords/memorization","display_name":"Memorization","score":0.47870001196861267},{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.4634999930858612},{"id":"https://openalex.org/keywords/randomized-experiment","display_name":"Randomized experiment","score":0.3978999853134155},{"id":"https://openalex.org/keywords/discriminative-model","display_name":"Discriminative model","score":0.388700008392334}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6611999869346619},{"id":"https://openalex.org/C158600405","wikidata":"https://www.wikidata.org/wiki/Q5054566","display_name":"Causal inference","level":2,"score":0.5936999917030334},{"id":"https://openalex.org/C2776436953","wikidata":"https://www.wikidata.org/wiki/Q5163215","display_name":"Consistency (knowledge bases)","level":2,"score":0.5794000029563904},{"id":"https://openalex.org/C185429906","wikidata":"https://www.wikidata.org/wiki/Q1130160","display_name":"Estimator","level":2,"score":0.560699999332428},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.5472999811172485},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5404999852180481},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.5311999917030334},{"id":"https://openalex.org/C30038468","wikidata":"https://www.wikidata.org/wiki/Q4354775","display_name":"Memorization","level":2,"score":0.47870001196861267},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.4634999930858612},{"id":"https://openalex.org/C155108698","wikidata":"https://www.wikidata.org/wiki/Q1231081","display_name":"Randomized experiment","level":2,"score":0.3978999853134155},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.388700008392334},{"id":"https://openalex.org/C134261354","wikidata":"https://www.wikidata.org/wiki/Q938438","display_name":"Statistical inference","level":2,"score":0.3831999897956848},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3797999918460846},{"id":"https://openalex.org/C11671645","wikidata":"https://www.wikidata.org/wiki/Q5054567","display_name":"Causal model","level":2,"score":0.37299999594688416},{"id":"https://openalex.org/C28719098","wikidata":"https://www.wikidata.org/wiki/Q44946","display_name":"Point (geometry)","level":2,"score":0.36419999599456787},{"id":"https://openalex.org/C2778712577","wikidata":"https://www.wikidata.org/wiki/Q3505966","display_name":"Retraining","level":2,"score":0.3587000072002411},{"id":"https://openalex.org/C167723999","wikidata":"https://www.wikidata.org/wiki/Q3773214","display_name":"Sampling distribution","level":2,"score":0.33709999918937683},{"id":"https://openalex.org/C87007009","wikidata":"https://www.wikidata.org/wiki/Q210832","display_name":"Statistical hypothesis testing","level":2,"score":0.33320000767707825},{"id":"https://openalex.org/C126042441","wikidata":"https://www.wikidata.org/wiki/Q1324888","display_name":"Frame (networking)","level":2,"score":0.3246000111103058},{"id":"https://openalex.org/C2776441110","wikidata":"https://www.wikidata.org/wiki/Q1436628","display_name":"Randomized response","level":3,"score":0.3109000027179718},{"id":"https://openalex.org/C207609745","wikidata":"https://www.wikidata.org/wiki/Q4944086","display_name":"Bootstrapping (finance)","level":2,"score":0.30799999833106995},{"id":"https://openalex.org/C150921843","wikidata":"https://www.wikidata.org/wiki/Q1170431","display_name":"Resampling","level":2,"score":0.30379998683929443},{"id":"https://openalex.org/C95167961","wikidata":"https://www.wikidata.org/wiki/Q4483495","display_name":"Fiducial inference","level":5,"score":0.28780001401901245},{"id":"https://openalex.org/C149782125","wikidata":"https://www.wikidata.org/wiki/Q160039","display_name":"Econometrics","level":1,"score":0.2712000012397766},{"id":"https://openalex.org/C41426520","wikidata":"https://www.wikidata.org/wiki/Q1192065","display_name":"Point estimation","level":2,"score":0.26969999074935913}],"mesh":[],"locations_count":2,"locations":[{"id":"pmh:doi:10.48550/arxiv.2602.02819","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},{"id":"doi:10.48550/arxiv.2602.02819","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2602.02819","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"pmh:doi:10.48550/arxiv.2602.02819","is_oa":true,"landing_page_url":null,"pdf_url":null,"source":{"id":"https://openalex.org/S4406922384","display_name":"Open MIND","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"Article"},"sustainable_development_goals":[{"display_name":"Reduced inequalities","score":0.6180769205093384,"id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Membership":[0],"Inference":[1],"Attacks":[2],"(MIAs)":[3],"are":[4,42,108],"widely":[5],"used":[6,44],"to":[7],"quantify":[8],"training":[9,31,78],"data":[10,34,74,139],"memorization":[11,66,146],"and":[12,36,84,122,129,153],"assess":[13],"privacy":[14,162],"risks.":[15],"Standard":[16],"evaluation":[17,59,163],"requires":[18],"repeated":[19],"retraining,":[20],"which":[21],"is":[22,151],"computationally":[23],"costly":[24],"for":[25,106,126,161],"large":[26],"models.":[27],"One-run":[28],"methods":[29,38,94],"(single":[30],"with":[32,132],"randomized":[33],"inclusion)":[35],"zero-run":[37,103,130],"(post":[39],"hoc":[40],"evaluation)":[41],"often":[43],"instead,":[45],"though":[46],"their":[47],"statistical":[48],"validity":[49],"remains":[50],"unclear.":[51],"To":[52],"address":[53],"this":[54],"gap,":[55],"we":[56],"frame":[57],"MIA":[58,120],"as":[60,67],"a":[61,73,158],"causal":[62,69,116],"inference":[63],"problem,":[64],"defining":[65],"the":[68,77],"effect":[70],"of":[71,88,118],"including":[72],"point":[75],"in":[76,90,164],"set.":[79],"This":[80],"novel":[81],"formulation":[82],"reveals":[83],"formalizes":[85],"key":[86],"sources":[87],"bias":[89],"existing":[91],"protocols:":[92],"one-run":[93],"suffer":[95],"from":[96],"interference":[97],"between":[98],"jointly":[99],"included":[100],"points,":[101],"while":[102],"evaluations":[104],"popular":[105],"LLMs":[107],"confounded":[109],"by":[110],"non-random":[111],"membership":[112],"assignment.":[113],"We":[114],"derive":[115],"analogues":[117],"standard":[119],"metrics":[121],"propose":[123],"practical":[124],"estimators":[125],"multi-run,":[127],"one-run,":[128],"regimes":[131],"non-asymptotic":[133],"consistency":[134],"guarantees.":[135],"Experiments":[136],"on":[137],"real-world":[138],"show":[140],"that":[141],"our":[142],"approach":[143],"enables":[144],"reliable":[145],"measurement":[147],"even":[148],"when":[149],"retraining":[150],"impractical":[152],"under":[154],"distribution":[155],"shift,":[156],"providing":[157],"principled":[159],"foundation":[160],"modern":[165],"AI":[166],"systems.":[167]},"counts_by_year":[],"updated_date":"2026-04-04T16:13:02.066488","created_date":"2026-02-06T00:00:00"}
