Abstract
Membership inference (MI) attacks pose significant privacy threats to machine learning models by determining whether specific data points were used during training. Existing MI methods rely on static heuristics and simple distance metrics that fail to capture the complex, nonlinear output manifolds of modern deep networks, where member and non-member distributions often overlap. We introduce DynaMI, a novel framework that addresses these limitations through two key innovations: (1) adaptive manifold projection using UMAP to better preserve discriminative information in latent space, and (2) counterfactual reasoning that actively probes membership status by analyzing how controlled perturbations affect sample classification. Unlike traditional approaches, DynaMI dynamically adapts to local output space geometry and operates effectively in blind inference scenarios without requiring shadow models or handcrafted thresholds. Our framework demonstrates superior performance across black-box and gray-box threat models, offering a more robust and semantically aware approach to membership inference in complex neural networks. DynaMI is evaluated across 8 diverse datasets using precision, recall, and F1-score metrics under both label-free and label-aware attack scenarios. Testing includes four non-member generation strategies and multiple latent-space kernels to assess framework robustness and adaptability. Performance is benchmarked against state-of-the-art defenses including MemGuard, MMD+Mixup, Adversarial Regularization, and DP-Adam.
Cite
CITATION STYLE
Kraidia, I., Qaddara, I., & Alraba’nah, Y. (2026). DynaMI: Dynamic Membership Inference via Adaptive Manifold Perturbations. IEEE Access. https://doi.org/10.1109/ACCESS.2026.3665297
Register to see more suggestions
Mendeley helps you to discover research relevant for your work.