Jadwal Sholat

Memuat jadwal sholatโ€ฆ

Ilmu Komputer & AI editorial

Open AccessOA2026

Subgroup Membership Inference Audits of Differentially Private Synthetic Text

A subgroup-targeted MIA audit reveals that DP synthetic text releases concentrate residual leakage in vulnerable subgroups, and that record-level risk is a property of the release mechanism, not the record alone.
Yidan Sun; Viktor Schlegel; Srinivasan Nandakumar; Siew Kei Lam; Anil Anthony Bharathยท 2026ยท DOI 10.48550/arXiv.2609.09848

The core problem

Synthetic data releases are increasingly proposed as a means of sharing realistic data replicas in lieu of sensitive private datasets. Even when the worst-case privacy leakage of such releases is bounded by means of differential privacy (DP), a residual risk remains in practice. Membership inference attack (MIA) audits are conducted to empirically quantify this risk.

However, existing methods only measure average-case risk for randomly drawn records, which might conceal the risk to vulnerable subgroups. To highlight this issue, the authors define a subgroup-targeted membership inference game in which the target pool is an explicit parameter. This reframing shifts the audit question from *does this release leak on average?* to *which subgroups does this release leak for, and how much?*

The work is positioned at the intersection of privacy auditing, synthetic text generation, and subgroup fairness in machine learning. The central claim is that aggregate DP guarantees and average-case audits can coexist with concentrated, subgroup-specific leakage that standard evaluations fail to surface.

Innovation

The audit shows that synthetic releases leak subgroup membership and that prior attacks systematically underestimate this leakage. This is the headline empirical finding: average-case MIA audits are not merely imprecise, they are biased in a direction that understates risk to vulnerable subgroups.

DP is effective at the aggregate level: it substantially reduces average leakage at every budget tested. This confirms that DP provides meaningful protection in the aggregate sense.

However, three observations temper this picture:

1. **Concentration of residual leakage.** Under DP, a tenth of the records carries roughly **40%** of the remaining leakage. Leakage is not spread evenly across the release; it is concentrated in a small fraction of records.
2. **Uneven protection.** Within its worst-case guarantee, the noise removes more of the measured leakage from random records than from high-risk ones. A merged-pool audit that scores both record types against shared negatives confirms this at the record level.
3. **Release-dependence of risk.** *Which* records leak proves to be a property of the release mechanism rather than of the record alone. Record-level risk cannot be assessed indep

Synthetic data releases are increasingly proposed as a means of sharing realistic data replicas in lieu of sensitive private datasets. Even when the worst-case privacy leakage of such releases is bounded by means of differential privacy (DP), a residual risk remains in practice. Membership inference attack (MIA) audits are conducted to empirically quantify this risk.
However, existing methods only measure average-case risk for randomly drawn records, which might conceal the risk to vulnerable subgroups. To highlight this issue, the authors define a subgroup-targeted membership inference game in which the target pool is an explicit parameter. This reframing shifts the audit question from *does this release leak on average?* to *which subgroups does this release leak for, and how much?*

Why it matters

The results carry several implications for how DP synthetic text releases are audited and deployed.

First, **average-case audits are insufficient for subgroup risk assessment**. If a tenth of records carries roughly 40% of residual leakage, then an audit that reports only an average will systematically understate the exposure of the most vulnerable records. Regulators, data protection officers, and release engineers relying on average-case MIA numbers may therefore underestimate real-world risk.

Second, **DP's practical protection is uneven within its worst-case guarantee**. The guarantee bounds worst-case leakage, but the empirical distribution of leakage under DP is not uniform. Noise removes more measured leakage from random records than from high-risk ones. This does not contradict DP theory, but it does complicate the translation from formal guarantee to empirical risk profile.

Third, **record-level risk is release-dependent**. Because *which* records leak is a property of the release mechanism rather than of the record alone, risk cannot be assessed by examining records in isolation. This has direct consequences for data-sharing workflows: the same record may be high-risk under one generator and low-risk under another, even at the same privacy budget.

Taken together, the findings argue for subgroup-aware auditing as a complement to, not a replacement for, formal DP analysis. The subgroup-targeted membership inference game provides a concrete methodological template for such audits.

Who should read this

CS practitioners and researchers

Opening member contentโ€ฆ