Evaluating Membership Inference Vulnerabilities in Variational Autoencoders with Differential Privacy

Trung Ha, Tran Khanh Dang · 2025

In recent years, Variational Autoencoders (VAEs) have attracted considerable interest due to their capability to generate high-fidelity data while safeguarding user privacy through differential privacy techniques. However, their vulnerability to membership inference attacks poses a significant challenge, as unauthorized access to membership information can result in privacy breaches. This research addressed the theoretical issue of assessing the privacy risks associated with VAEs while implementing differential privacy techniques to enhance data protection. This study meticulously investigated the vulnerabilities of VAEs in relation to membership inference, utilizing differential privacy to strengthen their defenses against such attacks. The assessment of VAE's efficacy in replicating member and non-member data under varying privacy constraints relies on analyzing the structural similarity index and attack precision. The experimental findings revealed that the Member_SSIM and Non_Member_SSIM values remained closely aligned, indicating a minimal risk of privacy leakage. Furthermore, both optimizers exhibited significant reductions in loss values, with DP-Adam consistently outperforming DP-SGD by achieving lower loss values for equivalent privacy budgets. This research provided compelling evidence that differential privacy techniques are effective in mitigating vulnerabilities to membership inference in VAEs.

Read the paper · More papers on PaperTik