Security & governance · Glossary term
What is Membership Inference?
An attack that estimates whether a particular record or example was included in a model's training data by observing model outputs or other accessible signals.
Why does Membership Inference matter?
Even when the model does not reproduce a record verbatim, distinguishable behavior can reveal information about participation in a sensitive dataset.
Membership Inference in practice
Test representative members and non-members under the real query interface, limit unnecessary confidence signals, reduce data exposure, and evaluate privacy defenses against utility requirements.
What is the common confusion about Membership Inference?
Membership inference asks whether a record participated in training. Model extraction tries to reproduce model behavior, while direct memorization tests whether content can be recovered.
Learn Membership Inference in the course
Start with
- Differential Privacy for LLMs
DP-SGD remains the standard — noise-injected gradient updates provide formal (epsilon, delta) guarantees. Overhead in compute, memory, and utility is substantial; parameter-efficient DP fine-tuning…
Taught in Phase 18: Ethics, Safety & Alignment.
Related terms
- Data LeakageUnintended use of information during training or feature construction that would not be available at the real prediction point or belongs…
- Data MinimizationFor personal data, limiting what is collected, processed, exposed, and retained to what is necessary for a specified purpose.
- Eval SetA versioned collection of inputs, expected properties, scoring rules, and metadata used to measure an AI system against a defined…
- Data ClassificationAssigning data to documented sensitivity or impact classes so handling, access, retention, sharing, and incident rules follow the…
Sources
More terms in Security & governance
- AI Risk Assessment
- Audit Log
- Content Provenance
- Data Classification
- Data Exfiltration
- Data Lineage
- Data Minimization
- Datasheet for Datasets
- Defense in Depth
- Indirect Prompt Injection
- Jailbreak
- Provenance Attestation
- Purpose Limitation
- Red Teaming
- Separation of Duties
- Software Bill of Materials (SBOM)
- Threat Model
- Trust Boundary
- Zero Trust
This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.