ReMIA: a Powerful and Efficient Alternative to Membership Inference Attacks against Synthetic Data Generators
This work addresses the vulnerability of synthetic data generators to membership inference attacks, noting that existing approaches incur substantial computational overhead and rely heavily on auxiliary data. To overcome these limitations, the authors propose ReMIA, an efficient and practical privacy risk assessment method that eliminates the need for shadow models. ReMIA requires only two rounds of generator training and no more auxiliary data than the size of the original training set, achieving high attack sensitivity through relative source discrimination rather than absolute membership prediction. Evaluated across multiple tabular datasets and generative models, a classifier-based implementation of ReMIA matches the attack performance of state-of-the-art methods while significantly reducing resource demands, further demonstrating that synthetic data offers a superior privacy-utility trade-off compared to traditional anonymization techniques.