Skip to yearly menu bar Skip to main content


You Only Query Once: An Efficient Label-Only Membership Inference Attack

Yutong Wu · Han Qiu · Shangwei Guo · Jiwei Li · Tianwei Zhang

Halle B #244
[ ]
Tue 7 May 7:30 a.m. PDT — 9:30 a.m. PDT


As one of the privacy threats to machine learning models, the membership inference attack (MIA) tries to infer whether a given sample is in the original training set of a victim model by analyzing its outputs. Recent studies only use the predicted hard labels to achieve impressive membership inference accuracy. However, such label-only MIA approach requires very high query budgets to evaluate the distance of the target sample from the victim model's decision boundary. We propose YOQO, a novel label-only attack to overcome the above limitation.YOQO aims at identifying a special area (called improvement area) around the target sample and crafting a query sample, whose hard label from the victim model can reliably reflect the target sample's membership. YOQO can successfully reduce the query budget from more than 1,000 times to only ONCE. Experiments demonstrate that YOQO is not only as effective as SOTA attack methods, but also performs comparably or even more robustly against many sophisticated defenses.

Chat is not available.