English

TAMIS: Tailored Membership Inference Attacks on Synthetic Data

Machine Learning 2025-11-13 v2 Machine Learning

Abstract

Membership Inference Attacks (MIA) enable to empirically assess the privacy of a machine learning algorithm. In this paper, we propose TAMIS, a novel MIA against differentially-private synthetic data generation methods that rely on graphical models. This attack builds upon MAMA-MIA, a recently-published state-of-the-art method. It lowers its computational cost and requires less attacker knowledge. Our attack is the product of a two-fold improvement. First, we recover the graphical model having generated a synthetic dataset by using solely that dataset, rather than shadow-modeling over an auxiliary one. This proves less costly and more performant. Second, we introduce a more mathematically-grounded attack score, that provides a natural threshold for binary predictions. In our experiments, TAMIS achieves better or similar performance as MAMA-MIA on replicas of the SNAKE challenge.

Keywords

Cite

@article{arxiv.2504.00758,
  title  = {TAMIS: Tailored Membership Inference Attacks on Synthetic Data},
  author = {Paul Andrey and Batiste Le Bars and Marc Tommasi},
  journal= {arXiv preprint arXiv:2504.00758},
  year   = {2025}
}

Comments

Accepted at ECML PKDD 2025 (Research Track). First published in Lecture Notes in Computer Science (LNAI), volume 16017, pp 203-220, in 2025 by Springer Nature. Version of Record: https://doi.org/10.1007/978-3-032-06096-9_12 This expanded version includes appendices that detail experimental results

R2 v1 2026-06-28T22:42:21.916Z