{"id":"https://openalex.org/W4415427964","doi":"https://doi.org/10.3233/faia251364","title":"Automatic Calibration for Membership Inference Attack on Large Language Models","display_name":"Automatic Calibration for Membership Inference Attack on Large Language Models","publication_year":2025,"publication_date":"2025-10-21","ids":{"openalex":"https://openalex.org/W4415427964","doi":"https://doi.org/10.3233/faia251364"},"language":null,"primary_location":{"id":"doi:10.3233/faia251364","is_oa":true,"landing_page_url":"https://doi.org/10.3233/faia251364","pdf_url":null,"source":{"id":"https://openalex.org/S4210201731","display_name":"Frontiers in artificial intelligence and applications","issn_l":"0922-6389","issn":["0922-6389","1879-8314"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Frontiers in Artificial Intelligence and Applications","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://doi.org/10.3233/faia251364","any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5093984391","display_name":"Saleh Zare Zade","orcid":null},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Saleh Zare Zade","raw_affiliation_strings":["Department of Computer Science, Wayne State University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"middle","author":{"id":null,"display_name":"Yao Qiang","orcid":null},"institutions":[{"id":"https://openalex.org/I177721651","display_name":"Oakland University","ror":"https://ror.org/01ythxj32","country_code":"US","type":"education","lineage":["https://openalex.org/I177721651"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yao Qiang","raw_affiliation_strings":["Department of Computer Science, Oakland University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Oakland University","institution_ids":["https://openalex.org/I177721651"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5060955674","display_name":"Xiangyu Zhou","orcid":"https://orcid.org/0009-0000-0776-8045"},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Xiangyu Zhou","raw_affiliation_strings":["Department of Computer Science, Wayne State University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102033635","display_name":"Hui Zhu","orcid":"https://orcid.org/0009-0003-7157-4933"},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hui Zhu","raw_affiliation_strings":["Department of Computer Science, Wayne State University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5093984392","display_name":"Mohammad Amin Roshani","orcid":null},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Mohammad Amin Roshani","raw_affiliation_strings":["Department of Computer Science, Wayne State University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015133769","display_name":"Prashant Khanduri","orcid":"https://orcid.org/0000-0003-3055-2917"},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Prashant Khanduri","raw_affiliation_strings":["Department of Computer Science, Wayne State University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University","institution_ids":["https://openalex.org/I185443292"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5009256505","display_name":"Dongxiao Zhu","orcid":"https://orcid.org/0000-0002-0225-7817"},"institutions":[{"id":"https://openalex.org/I185443292","display_name":"Wayne State University","ror":"https://ror.org/01070mq45","country_code":"US","type":"education","lineage":["https://openalex.org/I185443292"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dongxiao Zhu","raw_affiliation_strings":["Department of Computer Science, Wayne State University"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Wayne State University","institution_ids":["https://openalex.org/I185443292"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5093984391"],"corresponding_institution_ids":["https://openalex.org/I185443292"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.48884927,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9506999850273132,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10028","display_name":"Topic Modeling","score":0.9506999850273132,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7811999917030334},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6908000111579895},{"id":"https://openalex.org/keywords/calibration","display_name":"Calibration","score":0.5044000148773193},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.4377000033855438},{"id":"https://openalex.org/keywords/reliability","display_name":"Reliability (semiconductor)","score":0.42289999127388},{"id":"https://openalex.org/keywords/maximum-likelihood","display_name":"Maximum likelihood","score":0.4027999937534332},{"id":"https://openalex.org/keywords/language-model","display_name":"Language model","score":0.3928999900817871},{"id":"https://openalex.org/keywords/code","display_name":"Code (set theory)","score":0.3824000060558319}],"concepts":[{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7811999917030334},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7416999936103821},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6908000111579895},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5336999893188477},{"id":"https://openalex.org/C165838908","wikidata":"https://www.wikidata.org/wiki/Q736777","display_name":"Calibration","level":2,"score":0.5044000148773193},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.4377000033855438},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.43529999256134033},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4316999912261963},{"id":"https://openalex.org/C43214815","wikidata":"https://www.wikidata.org/wiki/Q7310987","display_name":"Reliability (semiconductor)","level":3,"score":0.42289999127388},{"id":"https://openalex.org/C49781872","wikidata":"https://www.wikidata.org/wiki/Q1045555","display_name":"Maximum likelihood","level":2,"score":0.4027999937534332},{"id":"https://openalex.org/C137293760","wikidata":"https://www.wikidata.org/wiki/Q3621696","display_name":"Language model","level":2,"score":0.3928999900817871},{"id":"https://openalex.org/C2776760102","wikidata":"https://www.wikidata.org/wiki/Q5139990","display_name":"Code (set theory)","level":3,"score":0.3824000060558319},{"id":"https://openalex.org/C95167961","wikidata":"https://www.wikidata.org/wiki/Q4483495","display_name":"Fiducial inference","level":5,"score":0.35850000381469727},{"id":"https://openalex.org/C160234255","wikidata":"https://www.wikidata.org/wiki/Q812535","display_name":"Bayesian inference","level":3,"score":0.3531999886035919},{"id":"https://openalex.org/C134261354","wikidata":"https://www.wikidata.org/wiki/Q938438","display_name":"Statistical inference","level":2,"score":0.3352000117301941},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.3271999955177307},{"id":"https://openalex.org/C149441793","wikidata":"https://www.wikidata.org/wiki/Q200726","display_name":"Probability distribution","level":2,"score":0.32249999046325684},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.31630000472068787},{"id":"https://openalex.org/C917703","wikidata":"https://www.wikidata.org/wiki/Q7239668","display_name":"Predictive inference","level":5,"score":0.31369999051094055},{"id":"https://openalex.org/C9357733","wikidata":"https://www.wikidata.org/wiki/Q6878417","display_name":"Missing data","level":2,"score":0.3052000105381012},{"id":"https://openalex.org/C107673813","wikidata":"https://www.wikidata.org/wiki/Q812534","display_name":"Bayesian probability","level":2,"score":0.26019999384880066}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.3233/faia251364","is_oa":true,"landing_page_url":"https://doi.org/10.3233/faia251364","pdf_url":null,"source":{"id":"https://openalex.org/S4210201731","display_name":"Frontiers in artificial intelligence and applications","issn_l":"0922-6389","issn":["0922-6389","1879-8314"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Frontiers in Artificial Intelligence and Applications","raw_type":"book-chapter"}],"best_oa_location":{"id":"doi:10.3233/faia251364","is_oa":true,"landing_page_url":"https://doi.org/10.3233/faia251364","pdf_url":null,"source":{"id":"https://openalex.org/S4210201731","display_name":"Frontiers in artificial intelligence and applications","issn_l":"0922-6389","issn":["0922-6389","1879-8314"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-nc","license_id":"https://openalex.org/licenses/cc-by-nc","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Frontiers in Artificial Intelligence and Applications","raw_type":"book-chapter"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"Membership":[0,65],"Inference":[1,66],"Attacks":[2],"(MIAs)":[3],"have":[4],"recently":[5],"been":[6],"employed":[7],"to":[8,34,74,103],"determine":[9],"whether":[10],"a":[11,35,59,71],"specific":[12],"text":[13],"was":[14],"part":[15],"of":[16,20,94,107,124],"the":[17,92,112,120],"pre-training":[18,93],"data":[19],"Large":[21],"Language":[22],"Models":[23],"(LLMs).":[24],"However,":[25],"existing":[26],"methods":[27],"often":[28],"misinfer":[29],"non-members":[30],"as":[31],"members,":[32],"leading":[33],"high":[36],"false":[37],"positive":[38],"rate,":[39],"or":[40],"depend":[41],"on":[42,129],"additional":[43],"reference":[44],"models":[45],"for":[46],"probability":[47,113],"calibration,":[48],"which":[49,69],"limits":[50],"their":[51],"practicality.":[52],"To":[53],"overcome":[54],"these":[55],"challenges,":[56],"we":[57],"introduce":[58,97],"novel":[60],"framework":[61],"called":[62],"Automatic":[63],"Calibration":[64],"Attack":[67],"(ACMIA),":[68],"utilizes":[70],"tunable":[72],"temperature":[73],"calibrate":[75],"output":[76],"probabilities":[77],"effectively.":[78],"This":[79],"approach":[80],"is":[81,138,155],"inspired":[82],"by":[83],"our":[84,135],"theoretical":[85],"insights":[86],"into":[87],"maximum":[88],"likelihood":[89],"estimation":[90],"during":[91],"LLMs.":[95],"We":[96],"ACMIA":[98],"in":[99],"three":[100,148],"configurations":[101],"designed":[102],"accommodate":[104],"different":[105],"levels":[106],"model":[108],"access":[109],"and":[110,117,122,142],"increase":[111],"gap":[114],"between":[115],"members":[116],"non-members,":[118],"improving":[119],"reliability":[121],"robustness":[123],"membership":[125],"inference.":[126],"Extensive":[127],"experiments":[128],"various":[130],"open-source":[131],"LLMs":[132],"demonstrate":[133],"that":[134],"proposed":[136],"attack":[137],"highly":[139],"effective,":[140],"robust,":[141],"generalizable,":[143],"surpassing":[144],"state-of-the-art":[145],"baselines":[146],"across":[147],"widely":[149],"used":[150],"benchmarks.":[151],"The":[152],"source":[153],"code":[154],"publicly":[156],"available.":[157]},"counts_by_year":[],"updated_date":"2026-04-16T08:26:57.006410","created_date":"2025-10-24T00:00:00"}
