Assessing Membership Inference Privacy Risks in Medical Diffusion Models via Discrete Encoding-Based Inference
Abstract
1. Introduction
- We extend the DDCM methodology to be compatible with general diffusion architectures beyond standard DDPM and optimize the efficiency. Based on this, we propose the Discrete Encoding-Based membership inference attack (DEB). By performing statistical analysis on the model’s outputs under discrete noise injection, DEB significantly improves membership inference performance.
- We perform a rigorous evaluation of MIA performance across diverse data domains, encompassing natural images, text-to-image models, and a carefully selected subset of medical image modalities. Our results reveal a complex landscape of membership inference privacy risks: vulnerability is highly dependent on the specific data modality and its semantic variance, finding that specific modalities that possess natural defense mechanisms against memorization.
- We validate the proposed DEB algorithm across these diverse domains. Experimental results demonstrate that DEB maintains superior performance, establishing significant advantages on natural images and unconditional text-to-image generation, while remaining superior performance on “hard” medical datasets where existing baselines struggle. Furthermore, we provide a comprehensive analysis of hyperparameters and demonstrate that the computational complexity of DEB remains highly tractable, requiring manageable execution time and GPU memory for practical deployment.
2. Related Work
2.1. Diffusion Models
2.2. Denoising Diffusion Codebook Models
2.3. Defenses Against MIA
3. Materials and Methods
3.1. Datasets and Training Details
3.2. Baseline
3.3. Evaluation Metrics
3.4. Proposed Method
3.4.1. Generalizing DDCM
3.4.2. Discrete Encoding-Based Membership Inference Attack
| Algorithm 1 Discrete Encoding-Based Membership Inference Attack | |
|
1: Input: The start time , the end time , maximum noise time ratio , minimum noise time ratio , and for function r, total iteration number N, threshold , sample , DDPM model , init function , codebook size K and codebook grid size g, attack time , window size W, norm p. 2: Output: if is in member set. 3: _list = [], , , , 4: repeat | |
| 5: _list.append([] * | ▹ Equation (31) |
|
6: 7: until == 8: sample | |
| 9: , , | ▹ Equation (28) or Equation (29) |
|
10: _list = [], _list = [] 11: repeat 12: 13: sample | |
| 14: | ▹ Equation (27) |
|
15: _list[n] 16: | |
| 17: | ▹ Equation (32) |
| 18: | ▹ Equation (30) |
|
19: 20: _list.append(), _list.append() 21: until 22: do DDIM 23: apply windowed averaging with size W to _list and _list. 24: target _list[] or target _list[] 25: if target then 26: return True 27: else 28: return False 29: end if | |
4. Results
4.1. Attack Performance on Medical Images
4.2. Attack Performance on Natural Images
4.3. Necessity of the Codebook Strategy
- Type-1, Continuous Random Perturbation: We initialize the sample by sampling from the distribution (i.e., adding noise to the original sample). In each iteration, we inject random Gaussian noise, perform a denoising step via the model, and then re-inject new noise for the subsequent step. Throughout this process, we record the model outputs and the reconstructed samples at each step.
- Type-2, Perturbation with Re-initialization: This setup shares the same initialization as the first method. However, to prevent the sample trajectory from deviating significantly from the original data point due to cumulative noise injection, we explicitly re-initialize the sample to the starting state after each denoising step. We similarly record the model outputs for each iteration.
4.4. Parameters’ Sensitivity Analysis
4.5. Settings of Hyperparameters
5. Discussion and Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Data Availability Statement
DURC Statement
Acknowledgments
Conflicts of Interest
Abbreviations
| DDPM | Denoising Diffusion Probabilistic Model |
| T1F | True Positive Rate (TPR) at a fixed False Positive Rate (FPR) of 1% (TPR @ 1% FPR) |
| MIA | Membership Inference Attack |
References
- Ho, J.; Jain, A.; Abbeel, P. Denoising diffusion probabilistic models. In Proceedings of the 34th Conference on Neural Information Processing Systems (NeurIPS 2020), Vancouver, Canada, 6–12 December 2020; pp. 6840–6851. [Google Scholar]
- Rombach, R.; Blattmann, A.; Lorenz, D.; Esser, P.; Ommer, B. High-resolution image synthesis with latent diffusion models. In Proceedings of the IEEE conference on Computer Vision and Pattern Recognition, Denver, CO, USA, 2–6 June 2022; pp. 10684–10695. [Google Scholar]
- Ramesh, A.; Dhariwal, P.; Nichol, A.; Chu, C.; Chen, M. Hierarchical text-conditional image generation with clip latents. arXiv 2022, arXiv:2204.06125. [Google Scholar] [CrossRef] [Scilit]
- Saharia, C.; Chan, W.; Saxena, S.; Li, L.; Whang, J.; Denton, E.L.; Ghasemipour, K.; Gontijo Lopes, R.; Karagol Ayan, B.; Salimans, T.; et al. Photorealistic text-to-image diffusion models with deep language understanding. In Proceedings of the 36th Conference on Neural Information Processing Systems (NeurIPS 2022), New Orleans, LA, USA, 28 November–9 December 2022; pp. 36479–36494. [Google Scholar]
- Goodfellow, I.; Pouget-Abadie, J.; Mirza, M.; Xu, B.; Warde-Farley, D.; Ozair, S.; Courville, A.; Bengio, Y. Generative adversarial networks. Commun. ACM 2020, 63, 139–144. [Google Scholar] [CrossRef] [Scilit]
- Brock, A.; Donahue, J.; Simonyan, K. Large Scale GAN Training for High Fidelity Natural Image Synthesis. In Proceedings of the International Conference on Learning Representations, New Orleans, LA, USA, 6–9 May 2019. [Google Scholar]
- Zhang, H.; Zhang, Z.; Odena, A.; Lee, H. Consistency Regularization for Generative Adversarial Networks. In Proceedings of the International Conference on Learning Representations, Addis Ababa, Ethiopia, 26–30 April 2020. [Google Scholar]
- Gulrajani, I.; Ahmed, F.; Arjovsky, M.; Dumoulin, V.; Courville, A.C. Improved training of wasserstein gans. In Proceedings of the 31st Annual Conference on Neural Information Processing Systems (NIPS 2017), Long Beach, California, USA, 4–9 December 2017; Volume 30. [Google Scholar]
- Kingma, D.P.; Welling, M. Auto-encoding variational bayes. arXiv 2013, arXiv:1312.6114. [Google Scholar]
- Bieder, F.; Wolleb, J.; Durrer, A.; Sandkühler, R.; Cattin, P.C. Diffusion models for memory-efficient processing of 3d medical images. arXiv 2023, arXiv:2303.15288. [Google Scholar] [CrossRef] [Scilit]
- Kim, B.; Oh, Y.; Ye, J.C. Diffusion Adversarial Representation Learning for Self-supervised Vessel Segmentation. In Proceedings of the International Conference on Learning Representations, Kigali, Rwanda, 1–5 May 2023. [Google Scholar]
- Rahman, A.; Valanarasu, J.M.J.; Hacihaliloglu, I.; Patel, V.M. Ambiguous medical image segmentation using diffusion models. In Proceedings of the IEEE/CVF conference on Computer Vision and Pattern Recognition, Vancouver, BC, Canada, 18–22 June 2023; pp. 11536–11546. [Google Scholar]
- Wang, X.; Shen, Z.; Song, Z.; Wang, S.; Liu, M.; Zhang, L.; Xuan, K.; Wang, Q. Arbitrary reduction of MRI inter-slice spacing using hierarchical feature conditional diffusion. In Machine Learning in Medical Imaging, Proceedings of the 14th International Workshop, MLMI 2023, Held in Conjunction with MICCAI 2023, Vancouver, BC, Canada, 8 October 2023, Proceedings, Part I; Springer: Cham, Switzerland, 2023; pp. 23–32. [Google Scholar]
- Chung, H.; Lee, E.S.; Ye, J.C. MR image denoising and super-resolution using regularized reverse diffusion. IEEE Trans. Med Imaging 2022, 42, 922–934. [Google Scholar] [CrossRef] [Scilit]
- Levac, B.; Jalal, A.; Tamir, J.I. Accelerated motion correction for MRI using score-based generative models. In Proceedings of the IEEE International Symposium on Biomedical Imaging, Cartagena, Colombia, 18-21 April 2023; IEEE: New York, NY, USA, 2023; pp. 1–5. [Google Scholar]
- Chung, H.; Ye, J.C. Score-based diffusion models for accelerated MRI. Med. Image Anal. 2022, 80, 102479. [Google Scholar] [CrossRef] [Scilit]
- Li, H.; Ditzler, G.; Roveda, J.; Li, A. Descod-ecg: Deep score-based diffusion model for ecg baseline wander and noise removal. IEEE J. Biomed. Health Inform. 2023, 28, 5081–5091. [Google Scholar] [CrossRef] [Scilit]
- Lyu, Q.; Wang, G. Conversion between CT and MRI images using diffusion and score-matching models. arXiv 2022, arXiv:2209.12104. [Google Scholar] [CrossRef] [Scilit]
- Li, Y.; Shao, H.C.; Liang, X.; Chen, L.; Li, R.; Jiang, S.; Wang, J.; Zhang, Y. Zero-shot medical image translation via frequency-guided diffusion models. IEEE Trans. Med Imaging 2023, 43, 980–993. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Liu, J.; Anirudh, R.; Thiagarajan, J.J.; He, S.; Mohan, K.A.; Kamilov, U.S.; Kim, H. Dolce: A model-based probabilistic diffusion framework for limited-angle ct reconstruction. In Proceedings of the IEEE/CVF International Conference on Computer Vision, Paris, France, 2–6 October 2023; pp. 10498–10508. [Google Scholar]
- Wiggins, W.F.; Tejani, A.S. On the opportunities and risks of foundation models for natural language processing in radiology. Radiol. Artif. Intell. 2022, 4, e220119. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Ihalainen, J. Computer creativity: Artificial intelligence and copyright. J. Intellect. Prop. Law Pract. 2018, 13, 724–728. [Google Scholar] [CrossRef] [Scilit]
- Usynin, D.; Rueckert, D.; Kaissis, G. Beyond gradients: Exploiting adversarial priors in model inversion attacks. ACM Trans. Priv. Secur. 2023, 26, 1–30. [Google Scholar] [CrossRef] [Scilit]
- Wu, M.; Zhang, X.; Ding, J.; Nguyen, H.; Yu, R.; Pan, M.; Wong, S.T. Evaluation of inference attack models for deep learning on medical data. arXiv 2020, arXiv:2011.00177. [Google Scholar] [CrossRef] [Scilit]
- Gupta, U.; Stripelis, D.; Lam, P.K.; Thompson, P.; Ambite, J.L.; Ver Steeg, G. Membership inference attacks on deep regression models for neuroimaging. In Proceedings of the Medical Imaging with Deep Learning, Lübeck, Germany, 7-9 July 2021; PMLR: New York, NY, USA, 2021; pp. 228–251. [Google Scholar]
- Shokri, R.; Stronati, M.; Song, C.; Shmatikov, V. Membership inference attacks against machine learning models. In Proceedings of the IEEE Symposium on Security and Privacy, San Jose, CA, USA, 22-26 May 2017; IEEE: New York, NY, USA, 2017; pp. 3–18. [Google Scholar]
- Zhai, S.; Chen, H.; Dong, Y.; Li, J.; Shen, Q.; Gao, Y.; Su, H.; Liu, Y. Membership inference on text-to-image diffusion models via conditional likelihood discrepancy. In Proceedings of the 38th Conference on Neural Information Processing Systems (NeurIPS 2024), Vancouver, BC, Canada, 9–15 December 2024; Volume 37, pp. 74122–74146. [Google Scholar]
- Carlini, N.; Hayes, J.; Nasr, M.; Jagielski, M.; Sehwag, V.; Tramer, F.; Balle, B.; Ippolito, D.; Wallace, E. Extracting training data from diffusion models. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23), Anaheim, CA, USA, 9–11 August 2023; pp. 5253–5270. [Google Scholar]
- Lugmayr, A.; Danelljan, M.; Romero, A.; Yu, F.; Timofte, R.; Van Gool, L. Repaint: Inpainting using denoising diffusion probabilistic models. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA, 18–24 June 2022; pp. 11461–11471. [Google Scholar]
- Yeom, S.; Giacomelli, I.; Fredrikson, M.; Jha, S. Privacy risk in machine learning: Analyzing the connection to overfitting. In Proceedings of the IEEE Computer Security Foundations Symposium, Oxford, UK, 9-12 July 2018; IEEE: New York, NY, USA, 2018; pp. 268–282. [Google Scholar]
- Matsumoto, T.; Miura, T.; Yanai, N. Membership inference attacks against diffusion models. In Proceedings of the IEEE Security and Privacy Workshops, San Francisco, CA, USA, 25 May 2023; IEEE: New York, NY, USA, 2023; pp. 77–83. [Google Scholar]
- Hu, H.; Pang, J. Membership inference of diffusion models. arXiv 2023, arXiv:2301.09956. [Google Scholar]
- Duan, J.; Kong, F.; Wang, S.; Shi, X.; Xu, K. Are diffusion models vulnerable to membership inference attacks? In Proceedings of the 40th International Conference on Machine Learning, Honolulu, HI, USA, 23-29 July 2023; PMLR: New York, NY, USA, 2023; pp. 8717–8730. [Google Scholar]
- Song, J.; Meng, C.; Ermon, S. Denoising Diffusion Implicit Models. In Proceedings of the 9th International Conference on Learning Representations, Virtual Event, Austria, 3–7 May 2021. [Google Scholar]
- Kong, F.; Duan, J.; Ma, R.; Shen, H.T.; Shi, X.; Zhu, X.; Xu, K. An Efficient Membership Inference Attack for the Diffusion Model by Proximal Initialization. In Proceedings of the 12th International Conference on Learning Representations, Vienna, Austria, 7–11 May 2024. [Google Scholar]
- Rao, M.; Qu, B.; Moyer, D. Score-based Membership Inference on Diffusion Models. arXiv 2025, arXiv:2509.25003. [Google Scholar] [CrossRef] [Scilit]
- Ohayon, G.; Manor, H.; Michaeli, T.; Elad, M. Compressed Image Generation with Denoising Diffusion Codebook Models. In Proceedings of the 42nd International Conference on Machine Learning, Vancouver, BC, Canada, 13–19 July 2025. [Google Scholar]
- Song, Y.; Sohl-Dickstein, J.; Kingma, D.P.; Kumar, A.; Ermon, S.; Poole, B. Score-based generative modeling through stochastic differential equations. arXiv 2020, arXiv:2011.13456. [Google Scholar]
- Kaya, Y.; Hong, S.; Dumitras, T. On the effectiveness of regularization against membership inference attacks. arXiv 2020, arXiv:2006.05336. [Google Scholar]
- Kaya, Y.; Dumitras, T. When does data augmentation help with membership inference attacks? In Proceedings of the International Conference on Machine Learning, Virtual, 18-24 July 2021; PMLR: New York, NY, USA, 2021; pp. 5345–5355. [Google Scholar]
- Yin, Y.; Chen, K.; Shou, L.; Chen, G. Defending privacy against more knowledgeable membership inference attackers. In Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, Virtual Event Singapore, 14–18 August 2021; Association for Computing Machinery: New York, NY, USA, 2021; pp. 2026–2036. [Google Scholar]
- Huang, H. Defense against membership inference attack applying domain adaptation with addictive noise. J. Comput. Commun. 2021, 9, 92–108. [Google Scholar] [CrossRef]
- Huang, H.; Luo, W.; Zeng, G.; Weng, J.; Zhang, Y.; Yang, A. DAMIA: Leveraging domain adaptation as a defense against membership inference attacks. IEEE Trans. Dependable Secur. Comput. 2021, 19, 3183–3199. [Google Scholar] [CrossRef] [Scilit]
- Mazzone, F.; Van Den Heuvel, L.; Huber, M.; Verdecchia, C.; Everts, M.; Hahn, F.; Peter, A. Repeated knowledge distillation with confidence masking to mitigate membership inference attacks. In Proceedings of the 15th ACM Workshop on Artificial Intelligence and Security, Los Angeles, CA, USA, 11 November 2022; Association for Computing Machinery: New York, NY, USA, 2022; pp. 13–24. [Google Scholar]
- Zhang, T.; He, Z.; Lee, R.B. Privacy-preserving machine learning through data obfuscation. arXiv 2018, arXiv:1807.01860. [Google Scholar] [CrossRef] [Scilit]
- Wang, C.; Liu, G.; Huang, H.; Feng, W.; Peng, K.; Wang, L. MIASec: Enabling data indistinguishability against membership inference attacks in MLaaS. IEEE Trans. Sustain. Comput. 2019, 5, 365–376. [Google Scholar] [CrossRef] [Scilit]
- Webster, R.; Rabin, J.; Simon, L.; Jurie, F. Generating private data surrogates for vision related tasks. In Proceedings of the 2020 25th International Conference on Pattern Recognition (ICPR), Milan, Italy, 10-15 January 2021; IEEE: New York, NY, USA, 2021; pp. 263–269. [Google Scholar]
- Yang, R.; Ma, J.; Miao, Y.; Ma, X. Privacy-preserving generative framework for images against membership inference attacks. IET Commun. 2023, 17, 45–62. [Google Scholar] [CrossRef] [Scilit]
- Chen, J.; Guo, Y.; Zheng, Q.; Chen, H. Protect privacy of deep classification networks by exploiting their generative power. Mach. Learn. 2021, 110, 651–674. [Google Scholar] [CrossRef] [Scilit]
- Yang, J.; Shi, R.; Ni, B. MedMNIST Classification Decathlon: A Lightweight AutoML Benchmark for Medical Image Analysis. In Proceedings of the IEEE 18th International Symposium on Biomedical Imaging, Nice, France, 13-16 April 2021; IEEE: New York, NY, USA, 2021; pp. 191–195. [Google Scholar]
- Yang, J.; Shi, R.; Wei, D.; Liu, Z.; Zhao, L.; Ke, B.; Pfister, H.; Ni, B. MedMNIST v2-A large-scale lightweight benchmark for 2D and 3D biomedical image classification. Sci. Data 2023, 10, 41. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- He, K.; Zhang, X.; Ren, S.; Sun, J. Deep residual learning for image recognition. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA, 27–30 June 2016; pp. 770–778. [Google Scholar]
- Krizhevsky, A.; Hinton, G. Learning Multiple Layers of Features from Tiny Images; Technical Report; University of Toronto: Toronto, ON, Canada, 2009. [Google Scholar]
- Deng, J.; Dong, W.; Socher, R.; Li, L.J.; Li, K.; Fei-Fei, L. Imagenet: A large-scale hierarchical image database. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Miami, FL, USA, 20-25 June 2009; IEEE: New York, NY, USA, 2009; pp. 248–255. [Google Scholar]
- Pinkney, J.N.M. Pokemon BLIP Captions. 2022. Available online: https://huggingface.co/datasets/lambdalabs/pokemon-blip-captions/ (accessed on 24 January 2026).
- Carlini, N.; Chien, S.; Nasr, M.; Song, S.; Terzis, A.; Tramer, F. Membership inference attacks from first principles. In Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, USA, 22-26 May 2022; IEEE: New York, NY, USA, 2022; pp. 1897–1914. [Google Scholar]
- Karras, T.; Aittala, M.; Aila, T.; Laine, S. Elucidating the Design Space of Diffusion-Based Generative Models. In Proceedings of the 36th Conference on Neural Information Processing Systems (NeurIPS 2022), New Orleans, LA, USA, 28 November–9 December 2022. [Google Scholar]
- Li, A.C.; Prabhudesai, M.; Duggal, S.; Brown, E.; Pathak, D. Your diffusion model is secretly a zero-shot classifier. In Proceedings of the IEEE/CVF International Conference on Computer Vision, Paris, France, 2–6 October 2023; pp. 2206–2217. [Google Scholar]







| Methods | PathMNIST | ChestMNIST | DermaMNIST | OCTMNIST | PneumoniaMNIST | RetinaMNIST | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| AUC | ACC | AUC | ACC | AUC | ACC | AUC | ACC | AUC | ACC | AUC | ACC | |
| ResNet-18 (28) | 0.983 | 0.907 | 0.768 | 0.947 | 0.917 | 0.735 | 0.943 | 0.743 | 0.944 | 0.854 | 0.717 | 0.524 |
| ResNet-18 (224) | 0.989 | 0.909 | 0.773 | 0.947 | 0.920 | 0.754 | 0.958 | 0.763 | 0.956 | 0.864 | 0.710 | 0.493 |
| ResNet-50 (28) | 0.990 | 0.911 | 0.769 | 0.947 | 0.913 | 0.735 | 0.952 | 0.762 | 0.948 | 0.854 | 0.726 | 0.528 |
| ResNet-50 (224) | 0.989 | 0.892 | 0.773 | 0.948 | 0.912 | 0.731 | 0.958 | 0.776 | 0.962 | 0.884 | 0.716 | 0.511 |
| Methods | BreastMNIST | BloodMNIST | TissueMNIST | OrganAMNIST | OrganCMNIST | OrganSMNIST | ||||||
| AUC | ACC | AUC | ACC | AUC | ACC | AUC | ACC | AUC | ACC | AUC | ACC | |
| ResNet-18 (28) | 0.901 | 0.863 | 0.998 | 0.958 | 0.930 | 0.676 | 0.997 | 0.935 | 0.992 | 0.900 | 0.972 | 0.782 |
| ResNet-18 (224) | 0.891 | 0.833 | 0.998 | 0.963 | 0.933 | 0.681 | 0.998 | 0.951 | 0.994 | 0.920 | 0.974 | 0.778 |
| ResNet-50 (28) | 0.857 | 0.812 | 0.997 | 0.956 | 0.931 | 0.680 | 0.997 | 0.935 | 0.992 | 0.905 | 0.972 | 0.770 |
| ResNet-50 (224) | 0.866 | 0.842 | 0.997 | 0.950 | 0.932 | 0.680 | 0.998 | 0.947 | 0.993 | 0.911 | 0.975 | 0.785 |
| Name | Data Modality | # Samples | # Training/Validation/Test |
|---|---|---|---|
| PathMNIST | Colon Pathology | 107,180 | 89,996/10,004/7180 |
| ChestMNIST | Chest X-Ray | 112,120 | 78,468/11,219/22,433 |
| DermaMNIST | Dermatoscope | 10,015 | 7007/1003/2005 |
| OCTMNIST | Retinal OCT | 109,309 | 97,477/10,832/1000 |
| PneumoniaMNIST | Chest X-Ray | 5856 | 4708/524/624 |
| RetinaMNIST | Fundus Camera | 1600 | 1080/120/400 |
| BreastMNIST | Breast Ultrasound | 780 | 546/78/156 |
| BloodMNIST | Blood Cell Microscope | 17,092 | 11,959/1712/3421 |
| TissueMNIST | Kidney Cortex Microscope | 236,386 | 165,466/23,640/47,280 |
| OrganAMNIST | Abdominal CT | 58,850 | 34,581/6491/17,778 |
| OrganCMNIST | Abdominal CT | 23,660 | 13,000/2392/8268 |
| OrganSMNIST | Abdominal CT | 25,221 | 13,940/2452/8829 |
| Methods | ChestMNIST | TissueMNIST | OrganAMNIST | OCTMNIST | PathMNIST | |||||
|---|---|---|---|---|---|---|---|---|---|---|
| AUC | T1F | AUC | T1F | AUC | T1F | AUC | T1F | AUC | T1F | |
| Loss | 98.3 | 51.4 | 57.4 | 1.1 | 86.4 | 15.8 | 89.6 | 13.0 | 53.9 | 1.2 |
| SecMI | 99.7 | 93.8 | 73.5 | 1.9 | 89.6 | 26.9 | 87.1 | 13.4 | 63.2 | 1.1 |
| PIA | 99.9 | 97.5 | 74.5 | 1.1 | 94.0 | 36.8 | 93.2 | 15.4 | 54.1 | 1.1 |
| SimA | 99.4 | 84.0 | 70.4 | 1.2 | 91.9 | 30.6 | 93.3 | 14.1 | 64.9 | 1.2 |
| DEB | 99.6 | 95.6 | 80.1 | 15.8 | 85.1 | 30.4 | 91.9 | 19.9 | 67.2 | 10.2 |
| Methods | ChestMNIST0 | ChestMNIST1 | ChestMNIST2 | |||
|---|---|---|---|---|---|---|
| AUC | T1F | AUC | T1F | AUC | T1F | |
| Loss | 98.1 | 47.7 | 98.1 | 49.3 | 98.1 | 51.7 |
| SecMI | 99.6 | 91.2 | 99.8 | 96.6 | 99.6 | 89.0 |
| PIA | 99.7 | 94.6 | 99.8 | 96.8 | 99.8 | 95.4 |
| SimA | 99.2 | 72.3 | 99.1 | 72.0 | 99.3 | 77.5 |
| DEB | 99.6 | 95.9 | 99.6 | 94.9 | 99.5 | 94.2 |
| Methods | ChestMNIST3 | ChestMNIST4 | ChestMNIST5 | |||
| AUC | T1F | AUC | T1F | AUC | T1F | |
| Loss | 98.2 | 50.3 | 98.2 | 52.9 | 98.2 | 49.8 |
| SecMI | 99.9 | 98.0 | 99.7 | 92.7 | 99.8 | 95.0 |
| PIA | 99.8 | 97.2 | 99.7 | 94.3 | 99.8 | 96.2 |
| SimA | 99.3 | 77.9 | 99.2 | 73.8 | 99.1 | 71.1 |
| DEB | 99.7 | 95.6 | 99.5 | 94.4 | 99.5 | 92.6 |
| Methods | ChestMNIST | TissueMNIST | OrganAMNIST | OCTMNIST | PathMNIST | |||||
|---|---|---|---|---|---|---|---|---|---|---|
| AUC | T1F | AUC | T1F | AUC | T1F | AUC | T1F | AUC | T1F | |
| Loss | 100.0 | 100.0 | 96.3 | 31.4 | 97.5 | 63.2 | 98.0 | 27.2 | 80.1 | 1.2 |
| SecMI | 100.0 | 100.0 | 97.9 | 54.1 | 98.2 | 71.7 | 98.1 | 27.9 | 37.4 | 1.2 |
| PIA | 100.0 | 100.0 | 98.3 | 58.1 | 99.4 | 86.6 | 98.1 | 26.3 | 59.0 | 1.7 |
| SimA | 100.0 | 100.0 | 97.3 | 22.0 | 99.3 | 86.0 | 98.2 | 29.0 | 62.1 | 1.6 |
| DEB | 100.0 | 99.9 | 97.7 | 67.0 | 97.0 | 76.6 | 97.7 | 32.0 | 88.7 | 58.2 |
| Methods | ChestMNIST | PathMNIST | ||
|---|---|---|---|---|
| AUC | T1F | AUC | T1F | |
| Loss | 100.0 | 100.0 | 83.2 | 1.5 |
| SecMI | 100.0 | 100.0 | 83.5 | 4.3 |
| PIA | 100.0 | 100.0 | 86.2 | 12.3 |
| SimA | 100.0 | 100.0 | 85.8 | 10.1 |
| DEB | 100.0 | 100.0 | 88.6 | 69.6 |
| Methods | CIFAR10 | CIFAR100 | TN-IN | Query | |||
|---|---|---|---|---|---|---|---|
| AUC | T1F | AUC | T1F | AUC | T1F | ||
| GAN-Leaks | 64.6 | 2.8 | 45.9 | 1.9 | 45.7 | 1.0 | 2000 |
| Loss | 84.7 | 6.9 | 82.3 | 9.6 | 84.9 | 10.0 | 1 |
| SecMI | 88.1 | 9.1 | 87.6 | 11.1 | 89.4 | 12.7 | 12 |
| PIA | 88.5 | 13.7 | 89.4 | 19.6 | 89.6 | 17.1 | 2 |
| SimA | 90.5 | 35.9 | 89.9 | 38.8 | 89.8 | 21.7 | 1 |
| DEB | 93.4 | 60.3 | 94.3 | 58.1 | 95.6 | 73.9 | 180 |
| Methods | Weak Overfitting | Realistic Finetuning | Query | ||
|---|---|---|---|---|---|
| AUC | T1F | AUC | T1F | ||
| Loss | 79.6 | 6.0 | 66.0 | 2.82 | 1 |
| SecMI | 89.1 | 7.2 | 60.0 | 0.84 | 12 |
| PIA | 87.5 | 10.0 | 60.0 | 2.64 | 2 |
| SimA | 93.0 | 21.8 | 64.3 | 3.92 | 1 |
| CLiD | 99.3 | 97.8 | 93.3 | 61.4 | 15 |
| DEB | 97.5 | 86.8 | 83.2 | 30.0 | 140 |
| DEB (none) | 95.2 | 70.0 | 80.9 | 31.0 | 140 |
| CIFAR10 | CIFAR100 | TinyImageNet | |
|---|---|---|---|
| Type-1 | 85.4 | 86.3 | 85.7 |
| Type-2 | 82.3 | 83.1 | 83.0 |
| Hyperparameters | Model | |
|---|---|---|
| DDPM | Stable Diffusion | |
| K | 128 | 128 |
| g | 2 | 4 |
| W | 200 | 120 |
| 120 | 110 | |
| 120 | 110 | |
| 0.03 | 0.45 | |
| 0.97 | 0.97 | |
| 2.1 | 8 | |
| 2.1 | 4 | |
| Hyperparameters | 32 × 32 | 64 × 64 |
|---|---|---|
| Optimizer | adam | adam |
| Optimizer-Scheduler | constant | cosine |
| LR | 2 × | 1 × |
| Training Steps | 800k | 800k |
| Batch Size | 128 | 128 |
| GPR | RTX 4090 | RTX 4090 |
| GPU RAM | 10.5 G | 24 G |
| Training Time | 1 d 14 h | 3 d 11 h |
| Precision | 32FP | 32FP |
| T | 1000 | 1000 |
| ch_mult | [1, 2, 2, 2] | [1, 1, 2, 2, 4, 4] |
| ch | 128 | 128 |
| 1 × | 1 × | |
| 0.02 | 0.02 | |
| num_res_blocks | 2 | 2 |
| attn | [1] | [4] |
| Attack Time (bs 128) | 40 s | 120 s |
| Attack GPU RAM (bs 128) | 5 G | 15 G |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Kong, F.; Cheng, H.; Chen, T.; Shi, X.; Yuan, C. Assessing Membership Inference Privacy Risks in Medical Diffusion Models via Discrete Encoding-Based Inference. Appl. Sci. 2026, 16, 3140. https://doi.org/10.3390/app16073140
Kong F, Cheng H, Chen T, Shi X, Yuan C. Assessing Membership Inference Privacy Risks in Medical Diffusion Models via Discrete Encoding-Based Inference. Applied Sciences. 2026; 16(7):3140. https://doi.org/10.3390/app16073140
Chicago/Turabian StyleKong, Fei, Hao Cheng, Tianlong Chen, Xiaoshuang Shi, and Chenxi Yuan. 2026. "Assessing Membership Inference Privacy Risks in Medical Diffusion Models via Discrete Encoding-Based Inference" Applied Sciences 16, no. 7: 3140. https://doi.org/10.3390/app16073140
APA StyleKong, F., Cheng, H., Chen, T., Shi, X., & Yuan, C. (2026). Assessing Membership Inference Privacy Risks in Medical Diffusion Models via Discrete Encoding-Based Inference. Applied Sciences, 16(7), 3140. https://doi.org/10.3390/app16073140

