Dataset distillation compresses a large real dataset into a small synthetic one, enabling models trained on the synthetic data to achieve performance comparable to those trained on the real data. Although synthetic datasets are assumed to be privacy-preserving, we show that existing distillation methods can cause severe privacy leakage because synthetic datasets implicitly encode the weight trajectories of the distilled model, they become over-informative and exploitable by adversaries. To expose this risk, we introduce the Information Revelation Attack (IRA) against state-of-the-art distillation techniques. Experiments show that IRA accurately predicts both the distillation algorithm and model architecture, and can successfully infer membership and recover sensitive samples from the real dataset.
@article{arxiv.2603.01053,
title = {Turning Black Box into White Box: Dataset Distillation Leaks},
author = {Huajie Chen and Tianqing Zhu and Yuchen Zhong and Yang Zhang and Shang Wang and Feng He and Lefeng Zhang and Jialiang Shen and Minghao Wang and Wanlei Zhou},
journal= {arXiv preprint arXiv:2603.01053},
year = {2026}
}