Bilkent University
Department of Computer Engineering
M.S.THESIS PRESENTATION
Exploiting Explainable Artificial Intelligence (XAI) for One-Shot Membership Inference Attacks
Omar Hamdache
Master Student
(Supervisor: Asst.Prof.Sinem Sav )
Computer Engineering Department
Bilkent University
Abstract: This thesis investigates the privacy implications of releasing explanations together with predictions in machine-learning (ML) services. Although explainability is intended to make model behavior more transparent, the information it provides can also disclose characteristics of the data used to train the model. We introduce XposedMIA, a black-box membership inference attack (MIA) framework that makes a membership decision from a single service query by interpreting the returned explanation as evidence of the queried instance's proximity to the target model's decision boundary. In particular, the geometric properties of LIME's local surrogate are used to construct a boundary-distance proxy. We further apply this perspective to tabular counterfactual explanations and, for the first time, to visual counterfactual explanations generated for image classifiers. The framework requires neither access to confidence scores nor shadow-model construction. Its only preparatory stage is a one-time calibration procedure, which can operate with a labeled calibration set containing approximately 30 instances. Once calibrated, XposedMIA relies exclusively on the predicted label and its associated explanation for each target sample. Experimental results show that the attack can attain success rates of up to 0.95 under this one-query setting, demonstrating that explanation interfaces can create an additional avenue for membership leakage.
DATE: September 9, Wednesday @ 13:30
Place: EA 516