English

Membership Inference Attack Against Music Diffusion Models via Generative Manifold Perturbation

Sound 2026-02-03 v1

Abstract

Membership inference attacks (MIAs) test whether a specific audio clip was used to train a model, making them a key tool for auditing generative music models for copyright compliance. However, loss-based signals (e.g., reconstruction error) are weakly aligned with human perception in practice, yielding poor separability at the low false-positive rates (FPRs) required for forensics. We propose the Latent Stability Adversarial Probe (LSA-Probe), a white-box method that measures a geometric property of the reverse diffusion: the minimal time-normalized perturbation budget needed to cross a fixed perceptual degradation threshold at an intermediate diffusion state. We show that training members, residing in more stable regions, exhibit a significantly higher degradation cost.

Keywords

Cite

@article{arxiv.2602.01645,
  title  = {Membership Inference Attack Against Music Diffusion Models via Generative Manifold Perturbation},
  author = {Yuxuan Liu and Peihong Zhang and Rui Sang and Zhixin Li and Yizhou Tan and Yiqiang Cai and Shengchen Li},
  journal= {arXiv preprint arXiv:2602.01645},
  year   = {2026}
}
R2 v1 2026-07-01T09:30:56.276Z