<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>membership inference &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/membership-inference/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Tue, 22 Sep 2026 01:24:05 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>membership inference &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>AI Learns to Forget: New Hypernetwork Framework Enables Data-Free Unlearning</title>
		<link>https://scienmag.com/ai-learns-to-forget-new-hypernetwork-framework-enables-data-free-unlearning/</link>
		
		<dc:creator><![CDATA[Denise Maddox]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 01:24:05 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[AI safety]]></category>
		<category><![CDATA[catastrophic forgetting]]></category>
		<category><![CDATA[continual learning]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[hypernetworks]]></category>
		<category><![CDATA[machine unlearning]]></category>
		<category><![CDATA[membership inference]]></category>
		<category><![CDATA[neural networks]]></category>
		<category><![CDATA[parameter generation]]></category>
		<category><![CDATA[ResNet]]></category>
		<category><![CDATA[right to be forgotten]]></category>
		<category><![CDATA[task embeddings]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=205211</guid>

					<description><![CDATA[Researchers have developed a hypernetwork-based framework that lets continually learning AI systems erase specific tasks without access to the original data, while preventing both catastrophic forgetting and the relapse of supposedly forgotten knowledge.]]></description>
										<content:encoded><![CDATA[<p>Artificial intelligence systems are increasingly being asked to do something that sounds paradoxical: forget. As regulators around the world tighten data protection rules and the public grows wary of how personal information is used to train machine learning models, researchers have been racing to develop techniques that allow a trained neural network to expunge specific knowledge without the enormous expense of retraining from scratch. A new study published in the journal Machine Learning takes a significant step toward making that possible in one of the hardest settings imaginable—continual learning, where a model must keep absorbing new tasks over time while its access to old data slips away.</p>
<p>The research, led by Sayanta Adhikari, Vishnuprasadh Kumaravelu, and P. K. Srijith of the Bayesian Reasoning and Inference Lab at the Indian Institute of Technology Hyderabad, introduces a framework called UnCLe, short for a Hypernetwork Framework for Data-Free Unlearning and Continual Learning. The core insight is that machine unlearning—the deliberate removal of a task&#8217;s influence from a trained model—has almost always been designed with offline training in mind, where engineers retain full access to the original dataset. In continual learning, that assumption collapses. Data arrives task by task and is typically discarded after use, so when an unlearning request arrives, the original examples may simply no longer exist.</p>
<p>The team identified two failure modes that emerge when conventional unlearning is naively applied to continual learning environments. The first is catastrophic forgetting of retained tasks, a well-known pathology in which updating a network to remove one capability wipes out unrelated capabilities it was supposed to keep. The second is subtler and, in some ways, more troubling: catastrophic remembering, in which tasks that were supposedly unlearned resurface when the model later absorbs new information. A model that appears to have forgotten sensitive data can effectively relapse, undermining the very privacy guarantees that unlearning is meant to provide.</p>
<p>UnCLe attacks both problems by restructuring how the model&#8217;s parameters are produced in the first place. Instead of training a single monolithic network, the framework employs a hypernetwork—a network that generates the weights of another network—conditioned on compact task embeddings. Each task the system encounters is represented by its own embedding vector, and the hypernetwork maps that embedding to a full set of task-specific parameters. Learning a new task therefore means learning or refining an embedding, while the shared hypernetwork machinery remains stable across the entire sequence of operations.</p>
<p>Unlearning under this scheme becomes elegantly simple at the task level. To remove a task, the framework optimizes the hypernetwork so that, for that task&#8217;s embedding, it generates parameters that behave like noise. The generated network produces uniform, maximum-entropy outputs on the forgotten task—in other words, the model becomes maximally uncertain, exactly as if it had never seen the task at all. Crucially, this procedure does not require the original training data, which is precisely what makes it data-free. The optimization is guided by a mean squared error objective that pulls the generated parameters toward freshly sampled Gaussian noise, combined with a regularization term that anchors the hypernetwork&#8217;s outputs for all previously retained tasks, preventing collateral damage.</p>
<p>The choice of a noise-matching objective, rather than a direct norm penalty, turns out to matter a great deal. The authors show mathematically that averaging the squared distance to random Gaussian samples converges to the squared L2 norm of the parameters plus a constant, meaning the MSE objective implicitly drives the forgotten task&#8217;s parameters toward zero and its outputs toward a uniform distribution. But applying the L2 norm directly would, over repeated unlearning operations, drag the hypernetwork&#8217;s own shared weights toward zero and destabilize the whole system. By contrast, sampling a fresh noise target at each optimization step constrains the forget task only in distribution, acting as an implicit regularizer that preserves the shared representation. The researchers compared alternatives—including fixed noise targets, pure norm reduction, and simply discarding the task embedding—and found their approach achieved the best balance between erasing the target task and protecting retained performance.</p>
<p>Scaling a hypernetwork to generate all the weights of a modern convolutional backbone such as ResNet18 or ResNet50 presents its own engineering challenge, since the hypernetwork&#8217;s output layer would otherwise balloon to an impractical size. The team&#8217;s solution is chunked generation: the main network&#8217;s parameters are partitioned into roughly 200 chunks, each produced by a dedicated head of the hypernetwork conditioned on a unique chunk embedding concatenated with the task embedding. These chunk embeddings are frozen after the first task to guard against forgetting, and the final layer is split into specialized heads for weights, batch normalization parameters, and residual connection parameters, reducing redundancy and computational overhead.</p>
<p>The practical consequences of this design are striking. Because unlearning operates entirely in parameter space, its computational cost is dominated by the hypernetwork&#8217;s forward and backward passes and is essentially independent of dataset size and class count. The only term that grows over a sequence is the regularization over retained tasks, and it grows linearly in the number of tasks, not data points. In conventional replay-based unlearning adapted to continual settings, by contrast, the cost scales with a replay buffer whose size is difficult to budget in advance. The researchers also introduced an annealing strategy that shrinks the burn-in phase of each unlearning operation by ten percent per operation, exploiting forward transfer to cut unlearning time without degrading quality.</p>
<p>Empirical evaluations across sequential vision benchmarks—including Permuted-MNIST, a five-dataset suite combining MNIST, Fashion-MNIST, KMNIST, notMNIST and SVHN, CIFAR-100, and TinyImageNet—showed that UnCLe can perform long interleaved sequences of learning and unlearning requests, up to 30 operations on TinyImageNet, with minimal disruption to previously acquired knowledge. Measured against baselines including fine-tuning, retraining from scratch, and hypernetwork variants that rely on natural catastrophic forgetting, UnCLe performed on par or better across metrics, and strictly better on three of five measures with a ResNet-18 backbone. It also achieved membership inference attack accuracy closest to the ideal fifty percent, a key indicator that forgotten data is genuinely indistinguishable from never-seen data—a central concern for privacy.</p>
<p>Perhaps most importantly for real-world deployment, UnCLe prevented the relapse phenomenon that plagues conventional approaches: tasks unlearned by prior methods tend to creep back once new learning occurs, whereas UnCLe&#8217;s unlearned tasks stayed forgotten even as subsequent tasks were absorbed. The authors argue this has broad implications for responsible AI governance, from honoring the right to be forgotten under data protection law to stripping biased or harmful behaviors from deployed models without full retraining. At the same time, they caution that the very possibility of relapse under weaker methods underscores the need for robust verification mechanisms. With code released publicly, the framework offers a template for AI systems that can keep learning throughout their operational life while remaining accountable to demands that they forget on command.</p>
<p><strong>Subject of Research:</strong> A hypernetwork framework enabling data-free machine unlearning within continual learning settings</p>
<p><strong>Article Title:</strong> A Hypernetwork Framework for Data-Free Unlearning and Continual Learning</p>
<p><strong>Article References:</strong> A Hypernetwork Framework for Data-Free Unlearning and Continual Learning. (n.d.). <a href="https://doi.org/10.1007/s10994-026-07125-8" rel="noopener noreferrer">https://doi.org/10.1007/s10994-026-07125-8</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10994-026-07125-8" rel="noopener noreferrer">10.1007/s10994-026-07125-8</a></p>
<p><strong>Keywords:</strong> machine unlearning, continual learning, hypernetworks, data privacy, catastrophic forgetting, task embeddings, neural networks, AI safety, right to be forgotten, ResNet, membership inference, parameter generation</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">205211</post-id>	</item>
		<item>
		<title>Deep Learning&#8217;s Privacy Wars: New Survey Maps Attacks and Defenses</title>
		<link>https://scienmag.com/deep-learnings-privacy-wars-new-survey-maps-attacks-and-defenses/</link>
		
		<dc:creator><![CDATA[Blake Davidson]]></dc:creator>
		<pubDate>Sat, 12 Sep 2026 22:29:24 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[AI model vulnerability assessment]]></category>
		<category><![CDATA[attack and defense taxonomy in deep learning]]></category>
		<category><![CDATA[cloud-based deep learning privacy risks]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[deep learning]]></category>
		<category><![CDATA[Deep learning privacy attacks]]></category>
		<category><![CDATA[differential privacy]]></category>
		<category><![CDATA[evaluation metrics for AI privacy defenses]]></category>
		<category><![CDATA[federated learning]]></category>
		<category><![CDATA[gradient leakage]]></category>
		<category><![CDATA[homomorphic encryption]]></category>
		<category><![CDATA[large language models]]></category>
		<category><![CDATA[machine learning model security]]></category>
		<category><![CDATA[machine learning security]]></category>
		<category><![CDATA[membership inference]]></category>
		<category><![CDATA[model inversion]]></category>
		<category><![CDATA[model inversion and membership inference attacks]]></category>
		<category><![CDATA[neural network data leaks]]></category>
		<category><![CDATA[privacy attacks]]></category>
		<category><![CDATA[privacy defense strategies in AI]]></category>
		<category><![CDATA[privacy-preserving machine learning techniques]]></category>
		<category><![CDATA[reproducibility in machine learning security research]]></category>
		<category><![CDATA[secure multi-party computation]]></category>
		<category><![CDATA[systematic review of AI privacy threats]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=199252</guid>

					<description><![CDATA[A new systematic survey maps the full landscape of privacy attacks on deep learning and finds that while differential privacy remains the practical baseline and cryptography the strongest guarantee, large language model leakage is an urgent, under-benchmarked gap.]]></description>
										<content:encoded><![CDATA[<p>Deep learning has quietly become the engine behind decisions that shape human lives: diagnosing cancers, approving loans, guiding government policy. But the models that make these systems so powerful also carry a dangerous secret. Trained on sensitive personal data and increasingly outsourced to cloud providers for their enormous computational appetite, deep neural networks can leak the very information they were built to protect. A sweeping new survey published in Knowledge and Information Systems by Subhasish Ghosh and Amit Kr. Mandal of SRM University AP offers the most systematic accounting yet of this hidden battleground, cataloguing how attackers pry private data out of trained models and rigorously assessing which defenses actually work.</p>
<p>Using a PRISMA-style systematic review methodology, the researchers analyzed papers from the last five years of literature, the period in which privacy attacks against machine learning evolved from academic curiosities into practical threats. Their contribution is not a single new technique but a map of the entire battlefield: a unified taxonomy of attack families, a parallel taxonomy of defenses, recommended evaluation metrics for each attack type, and a reproducibility checklist alongside an attack-by-defense protection matrix that distills the qualitative findings of hundreds of studies into a single comparative view.</p>
<p>The taxonomy of attacks is sobering in its breadth. Membership inference attacks ask a deceptively simple question of a model: was this specific person&#8217;s record part of your training data? First demonstrated systematically by Shokri and colleagues in 2017 and refined since through approaches that exploit overfitting, prediction sensitivity, and quantile regression, these attacks now extend even to large language models, recommender systems, graph neural networks, and diffusion models. Model inversion attacks go further, reconstructing representative images or attributes of training classes from a model&#8217;s outputs, exploiting the confidence information that models emit so freely. Model extraction attacks steal entire architectures and weights through prediction APIs, converting years of training investment into a target for intellectual property theft as well as privacy abuse.</p>
<p>Perhaps most alarming for the federated learning era is gradient leakage. In collaborative training settings where participants share gradient updates instead of raw data, researchers showed as early as 2019 with the Deep Leakage from Gradients work that those updates can be inverted to reconstruct training inputs almost pixel-perfectly. The survey also covers property and attribute inference, in which adversaries deduce sensitive characteristics of training populations, alongside poisoning and backdoor attacks that corrupt models from within, side-channel attacks that exploit hardware implementations, and a rapidly growing family of large language model specific leakage, including verbatim training data extraction from production models and membership inference against in-context learning.</p>
<p>Against this arsenal, the survey organizes defenses into coherent families. Differential privacy, introduced by Cynthia Dwork in 2006, remains the workhorse: by injecting carefully calibrated noise into gradients during training, typically through the DP-SGD algorithm of Abadi and colleagues, it provides a mathematically provable bound on how much any single individual&#8217;s data can influence the model. The literature has spawned refinements including Rényi and Gaussian differential privacy, concentrated variants, adaptive gradient clipping, and privacy accounting improvements, along with integration into generative adversarial networks, Bayesian neural networks, and stochastic gradient Langevin dynamics.</p>
<p>Federated learning itself constitutes a second defense pillar, allowing organizations such as hospitals to train shared models without centralizing patient records, a principle already demonstrated in real multicenter studies for glaucoma detection, skin cancer diagnosis, and medical image analysis. Yet the survey is clear that federated learning alone is not privacy protection: gradient reconstruction, membership inference, and property inference all remain viable against naive federated systems, which is why the pairing with robust and privacy-preserving aggregation rules, secure aggregation protocols, and blockchain-based verification has become an active research frontier.</p>
<p>At the strongest end of the guarantee spectrum sit cryptographic approaches: homomorphic encryption, which permits computation directly on encrypted data, and secure multi-party computation, which distributes computation so no party sees another&#8217;s inputs. These techniques offer mathematically rigorous confidentiality, and standardized frameworks from IEEE and ITU now exist to guide their deployment. But the survey&#8217;s comparative analysis is unambiguous about the price: cryptographic stacks impose computational and communication overheads that can be orders of magnitude higher than plaintext training, making them practical today mainly for inference workloads, smaller models, or high-stakes domains such as healthcare and finance where the value of the data justifies the cost. Hybrid architectures, such as federated learning combined with homomorphic encryption or differential privacy layered over secure aggregation, attempt to balance these trade-offs.</p>
<p>The authors sharpen their analysis with three case studies covering centralized image classification, federated learning, and large language models. The verdict on the current landscape is nuanced. Noise-based methods such as differential privacy remain the practical baseline, deployable at scale and increasingly efficient, but they offer only partial protection, and their privacy-utility trade-off still forces difficult choices in accuracy-sensitive applications. Cryptographic methods deliver the strongest theoretical guarantees at substantially higher cost. Most urgently, the survey identifies large language model and multimodal leakage as an under-benchmarked gap: while training data extraction and membership inference against language models have been repeatedly demonstrated, standardized evaluation of defenses in this space lags far behind the pace of model deployment.</p>
<p>What makes this survey particularly valuable for practitioners is its insistence on evaluation discipline. For each attack family, the authors recommend specific metrics, recognizing, for example, that membership inference success should be measured against realistic background-knowledge assumptions rather than favorable shadow-model setups, and that privacy claims must be tested against adaptive attackers rather than fixed benchmarks. The reproducibility checklist addresses a chronic weakness of the field, where attack papers and defense papers often use incompatible threat models, making headline claims difficult to compare. The attack-by-defense protection matrix gives system designers a direct way to reason about which combination of techniques addresses which threats, and where residual risk remains.</p>
<p>The stakes of getting this right are rising alongside regulation. Data protection laws around the world increasingly impose concrete obligations on organizations whose models memorize personal information, and the survey situates the technical landscape within this regulatory context, noting that healthcare, finance, and government deployments face the tightest constraints. For the field as a whole, the message is one of guarded optimism paired with urgency. The defensive toolkit is now rich, mathematically grounded, and increasingly practical, and surveys like this one provide the coordination infrastructure the field has lacked. But as models grow larger, more multimodal, and more deeply embedded in everyday services, the attack surface grows with them, and the gap between what can be attacked and what has been rigorously defended remains widest precisely where the data is most personal. Closing that gap, the authors suggest, will require the same systematic, benchmark-driven rigor that this survey brings to mapping the problem.</p>
<p><strong>Subject of Research:</strong> Privacy-preserving methodologies and privacy attacks in deep learning</p>
<p><strong>Article Title:</strong> Privacy-preserving methodologies against privacy attacks on deep learning: a survey</p>
<p><strong>Article References:</strong> Ghosh, S., &amp; Mandal, A. K. (2026). Privacy-preserving methodologies against privacy attacks on deep learning: a survey. <em>Knowledge and Information Systems, 68</em>(1), Article 255. <a href="https://doi.org/10.1007/s10115-026-02865-4" rel="noopener noreferrer">https://doi.org/10.1007/s10115-026-02865-4</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s10115-026-02865-4" rel="noopener noreferrer">10.1007/s10115-026-02865-4</a></p>
<p><strong>Keywords:</strong> deep learning, privacy attacks, differential privacy, federated learning, homomorphic encryption, membership inference, model inversion, gradient leakage, large language models, secure multi-party computation, data privacy, machine learning security</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">199252</post-id>	</item>
	</channel>
</rss>
