An Indicator of Membership Inference Security in Post-Training Quantized Models

Eric AUBINAIS, Philippe Formont, Pablo Piantanida, Elisabeth Gassiat
Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, PMLR 300:649-657, 2026.

Abstract

Quantizing machine learning models has demonstrated its effectiveness in lowering memory and inference costs while maintaining performance levels comparable to those of the original models. In this work, we investigate the impact of quantization procedures on privacy in data-driven models, focusing on their vulnerability to membership inference attacks. Membership Inference Security (MIS) has recently been proposed to characterize the privacy of machine learning models against the most powerful (and possibly unknown) attacks. However, quantifying MIS appears to be computationally very difficult. In this paper, we propose a new MIS indicator for post-training quantization procedures of machine learning models that minimize an empirical loss. This new indicator is a byproduct of a theoretical asymptotic analysis of the MIS in this context. We also present a methodology for empirically estimating our MIS indicator. Using synthetic datasets and real-world data (in the context of drug discovery), we demonstrate the effectiveness of our approach in assessing and ranking the MIS of different quantizers.

Cite this Paper


BibTeX
@InProceedings{pmlr-v300-aubinais26a, title = { An Indicator of Membership Inference Security in Post-Training Quantized Models }, author = {AUBINAIS, Eric and Formont, Philippe and Piantanida, Pablo and Gassiat, Elisabeth}, booktitle = {Proceedings of The 29th International Conference on Artificial Intelligence and Statistics}, pages = {649--657}, year = {2026}, editor = {Khan, Emtiyaz and Li, Yingzhen and Solin, Arno and Ramdas, Aaditya}, volume = {300}, series = {Proceedings of Machine Learning Research}, month = {02--05 May}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v300/main/assets/aubinais26a/aubinais26a.pdf}, url = {https://proceedings.mlr.press/v300/aubinais26a.html}, abstract = { Quantizing machine learning models has demonstrated its effectiveness in lowering memory and inference costs while maintaining performance levels comparable to those of the original models. In this work, we investigate the impact of quantization procedures on privacy in data-driven models, focusing on their vulnerability to membership inference attacks. Membership Inference Security (MIS) has recently been proposed to characterize the privacy of machine learning models against the most powerful (and possibly unknown) attacks. However, quantifying MIS appears to be computationally very difficult. In this paper, we propose a new MIS indicator for post-training quantization procedures of machine learning models that minimize an empirical loss. This new indicator is a byproduct of a theoretical asymptotic analysis of the MIS in this context. We also present a methodology for empirically estimating our MIS indicator. Using synthetic datasets and real-world data (in the context of drug discovery), we demonstrate the effectiveness of our approach in assessing and ranking the MIS of different quantizers. } }
Endnote
%0 Conference Paper %T An Indicator of Membership Inference Security in Post-Training Quantized Models %A Eric AUBINAIS %A Philippe Formont %A Pablo Piantanida %A Elisabeth Gassiat %B Proceedings of The 29th International Conference on Artificial Intelligence and Statistics %C Proceedings of Machine Learning Research %D 2026 %E Emtiyaz Khan %E Yingzhen Li %E Arno Solin %E Aaditya Ramdas %F pmlr-v300-aubinais26a %I PMLR %P 649--657 %U https://proceedings.mlr.press/v300/aubinais26a.html %V 300 %X Quantizing machine learning models has demonstrated its effectiveness in lowering memory and inference costs while maintaining performance levels comparable to those of the original models. In this work, we investigate the impact of quantization procedures on privacy in data-driven models, focusing on their vulnerability to membership inference attacks. Membership Inference Security (MIS) has recently been proposed to characterize the privacy of machine learning models against the most powerful (and possibly unknown) attacks. However, quantifying MIS appears to be computationally very difficult. In this paper, we propose a new MIS indicator for post-training quantization procedures of machine learning models that minimize an empirical loss. This new indicator is a byproduct of a theoretical asymptotic analysis of the MIS in this context. We also present a methodology for empirically estimating our MIS indicator. Using synthetic datasets and real-world data (in the context of drug discovery), we demonstrate the effectiveness of our approach in assessing and ranking the MIS of different quantizers.
APA
AUBINAIS, E., Formont, P., Piantanida, P. & Gassiat, E.. (2026). An Indicator of Membership Inference Security in Post-Training Quantized Models . Proceedings of The 29th International Conference on Artificial Intelligence and Statistics, in Proceedings of Machine Learning Research 300:649-657 Available from https://proceedings.mlr.press/v300/aubinais26a.html.

Related Material