Model Privacy Attacks

Membership inference · model extraction · privacy risk evaluation · Adult/OpenML · breast_cancer · Source repo ↗
Static benchmark data from committed results/*.json artifacts. Committed Adult/OpenML DirectMIA benchmark: mean ROC AUC 0.557 across 5 seeds, with a 95% across-seed CI of 0.5525–0.5615. A separate breast-cancer benchmark reports AUC 0.4541. Results are dataset/model specific and must not be generalized.
0.557
Adult MI mean AUC
5 independent seeds
0.5525–0.5615
Across-seed 95% CI
Student t-interval
0.4541
Breast-cancer MIA AUC
Separate real benchmark
0.1293
Adult generalization gap
train 0.9927 · test 0.8634
Adult/OpenML DirectMIA evidence
Mean ROC AUC
0.557
Train accuracy
0.9927
Test accuracy
0.8634

Source: results/adult_mia_auc_ci_benchmark.json. Five seeds (42–46), 48,842 samples, GradientBoostingClassifier.

Claim boundary

The 0.557 value is a dataset/model-specific membership-inference result, not a universal privacy-risk score. A separate committed breast-cancer benchmark reports MIA AUC 0.4541. DP-SGD, extraction, and inversion capabilities must not be assigned headline effectiveness numbers unless a matching committed benchmark artifact exists.