Publication: Win-k: improved membership inference attacks on small language models
| dc.conference.date | SEP 22-24, 2025 | |
| dc.contributor.coauthor | Arkhmammadova, R. | |
| dc.contributor.coauthor | Tamar, H. M. | |
| dc.contributor.coauthor | Gursoy, M. E. | |
| dc.contributor.department | Graduate School of Sciences and Engineering | |
| dc.contributor.department | Department of Computer Engineering | |
| dc.contributor.kuauthor | Arkhmammadova, Roya | |
| dc.contributor.kuauthor | Gürsoy, Mehmet Emre | |
| dc.contributor.kuauthor | Tamar, Hosein Madadi | |
| dc.contributor.schoolcollegeinstitute | GRADUATE SCHOOL OF SCIENCES AND ENGINEERING | |
| dc.contributor.schoolcollegeinstitute | College of Engineering | |
| dc.date.accessioned | 2026-08-14T11:27:59Z | |
| dc.date.issued | 2026 | |
| dc.description.abstract | Small language models (SLMs) are increasingly valued for their efficiency and deployability in resource-constrained environments, making them useful for on-device, privacy-sensitive, and edge computing applications. On the other hand, membership inference attacks (MIAs), which aim to determine whether a given sample was used in a model’s training, are an important threat with serious privacy and intellectual property implications. In this paper, we study MIAs on SLMs. Although MIAs were shown to be effective on large language models (LLMs), they are relatively less studied on emerging SLMs, and furthermore, their effectiveness decreases as models get smaller. Motivated by this finding, we propose a new MIA called win-k, which builds on top of a state-of-the-art attack (min-k). We experimentally evaluate win-k by comparing it with five existing MIAs using three datasets and eight SLMs. Results show that win-k outperforms existing MIAs in terms of AUROC, TPR @ 1% FPR, and FPR @ 99% TPR metrics, especially on smaller models. | |
| dc.description.harvestedfrom | Manual | |
| dc.description.indexedby | Scopus | |
| dc.description.publisherscope | International | |
| dc.description.readpublish | N/A | |
| dc.description.sponsoredbyTubitakEu | TÜBİTAK | |
| dc.description.sponsorship | This study was supported by The Scientific and Technological Research Council of Turkiye (TUBITAK) under grants numbered 123E179 and 125E059. The authors thank TUBITAK for their support | |
| dc.description.version | Published Version | |
| dc.identifier.ScopusPercentile | 53 | |
| dc.identifier.ScopusQuartile | Q2 | |
| dc.identifier.WoSPercentile | N/A | |
| dc.identifier.WoSQuartile | N/A | |
| dc.identifier.doi | 10.1007/978-3-032-16089-8_5 | |
| dc.identifier.eissn | 1611-3349 | |
| dc.identifier.embargo | N/A | |
| dc.identifier.endpage | 78 | |
| dc.identifier.grantno | 123E179 | |
| dc.identifier.grantno | 125E059 | |
| dc.identifier.isbn | 9783032160881 | |
| dc.identifier.issn | 0302-9743 | |
| dc.identifier.scopus | 2-s2.0-105039336485 | |
| dc.identifier.startpage | 66 | |
| dc.identifier.uri | http://doi.org/10.1007/978-3-032-16089-8_5 | |
| dc.identifier.uri | https://hdl.handle.net/20.500.14288/34700 | |
| dc.keywords | AI security | |
| dc.keywords | Membership inference attacks | |
| dc.keywords | Privacy | |
| dc.keywords | Responsible AI | |
| dc.keywords | Small language models | |
| dc.language | eng | |
| dc.publisher | Springer | |
| dc.relation.affiliation | Koç University | |
| dc.relation.collection | Koç University Institutional Repository | |
| dc.relation.ispartof | Lecture Notes in Computer Science | |
| dc.relation.openaccess | N/A | |
| dc.rights | N/A | |
| dc.rights.uri | N/A | |
| dc.subject | Computer engineering | |
| dc.subject | Computer science | |
| dc.subject | Artificial intelligence | |
| dc.title | Win-k: improved membership inference attacks on small language models | |
| dc.type | Conference Proceeding | |
| dspace.entity.type | Publication | |
| relation.isOrgUnitOfPublication | 3fc31c89-e803-4eb1-af6b-6258bc42c3d8 | |
| relation.isOrgUnitOfPublication | 89352e43-bf09-4ef4-82f6-6f9d0174ebae | |
| relation.isOrgUnitOfPublication.latestForDiscovery | 3fc31c89-e803-4eb1-af6b-6258bc42c3d8 | |
| relation.isParentOrgUnitOfPublication | 434c9663-2b11-4e66-9399-c863e2ebae43 | |
| relation.isParentOrgUnitOfPublication | 8e756b23-2d4a-4ce8-b1b3-62c794a8c164 | |
| relation.isParentOrgUnitOfPublication.latestForDiscovery | 434c9663-2b11-4e66-9399-c863e2ebae43 |
