Membership Inference Attack Against Bayesian Neural Network

Toshiki Shibahara, Takayuki Miura, Masanobu Kii, Atsunori Ichikawa · 2025

Membership Inference Attacks (MIAs) have been actively studied to evaluate the privacy risks of training data. However, existing MIAs focus on deterministic deep neural networks (DNNs). In this paper, we extend MIAs against deterministic DNNs to be applicable to Bayesian NNs (BNNs) and evaluate the privacy risks of BNNs. Specifically, we propose four MIAs, each differing in the extent to which detailed information on the posterior predictive distribution is exploited. Additionally, considering the trait of BNNs that produce different outputs for the same input, we also propose four multiple query attacks where attackers query BNNs multiple times using the same data and conduct MIAs with aggregated outputs. We conducted experiments using two tabular datasets for regression tasks and three representative BNNs. Our experiments show that outputting more detailed information on the posterior predictive distribution poses a higher privacy risk. Additionally, we found that the privacy risks may be underestimated if attackers exploiting multiple queries are not assumed.

Read the paper · More papers on PaperTik