Skip to content
AI Atlas
PaperActive

Predicting Privacy Leakage from Weight Spectral Density

arxiv.org/abs/2609.11780

Updated 29 min ago · first seen 11 Sept 2026

paper_01M294FPBTHEE4K3VDT2GK6D2M

Published
11 Sept 2026
T1 · 29 min ago
arXiv
2609.11780
T1 · 29 min ago
Category
cs.LG
T1 · 29 min ago

Abstract

Membership inference attacks (MIAs) are widely used to audit the privacy disclosure risk of machine learning models, however current state-of-the-art attacks require training computationally expensive shadow models, making large-scale privacy evaluation impractical. In this work, we investigate whether inexpensive spectral metrics derived from the heavy-tailed self-regularisation framework can serve as proxies for MIA vulnerability. We evaluate several WeightWatcher spectral metrics on image and tabular classification tasks and compare their relationship with MIA privacy leakage against conventional measures of generalisation. Across datasets, stable rank exhibits a strong positive correlation with overall MIA success, while Log alpha-Norm shows a consistent negative correlation with MIA vulnerability at the low false-positive regime. These associations are observed to be stronger than those obtained using the generalisation gap. The results indicate that neural network spectra may contain information about privacy leakage that is not fully captured by conventional measures of overfitting, motivating spectral analysis as a promising direction for scalable privacy auditing.

Authors 2

Richard J. Preen, Jim Smith

Specification

Official page

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

Arxiv announce type
new

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

arXiv id
2609.11780

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

Categories
cs.LG, cs.CR, cs.NE

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

PDF

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

Primary category
cs.LG

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

Published
11 Sept 2026

Source:arXiv (Atom API + RSS)T1observed 29 min agohigh

Each value shows its source, tier and observation time. Conflicting claims are kept side by side and flagged — never averaged. How AI Atlas records facts →

Provenance

Attributed facts

9

Source tiers

T19

Freshest observation

29 min ago

Conflicts

None