Arrow Research search
Back to NeurIPS

NeurIPS 2025

Practical Bayes-Optimal Membership Inference Attacks

Conference Paper Main Conference Track Artificial Intelligence ยท Machine Learning

Abstract

We develop practical and theoretically grounded membership inference attacks (MIAs) against both independent and identically distributed (i. i. d. ) data and graph-structured data. Building on the Bayesian decision-theoretic framework of Sabrayolles et al. , we derive the Bayes-optimal membership inference rule for node-level MIAs against graph neural networks, addressing key open questions about optimal query strategies in the graph setting. We introduce BASE and G-BASE, tractable approximations of the Bayes-optimal membership inference. G-BASE achieves superior performance compared to previously proposed classifier-based node-level MIA attacks. BASE, which is also applicable to non-graph data, matches or exceeds the performance of prior state-of-the-art MIAs, such as LiRA and RMIA, at a significantly lower computational cost. Finally, we show that BASE and RMIA are equivalent under a specific hyperparameter setting, providing a principled, Bayes-optimal justification for the RMIA attack.

Authors

Keywords

No keywords are indexed for this paper.

Context

Venue
Annual Conference on Neural Information Processing Systems
Archive span
1987-2025
Indexed papers
30776
Paper id
729275854142031276
v2026.09.13