Where Flow Matching Leaks: Characterising the Membership Signals Along the Interpolation Path

Thomas Sesmat, Gabriel Meseguer-Brocal, Geoffroy Peeters
Proceedings of the 43rd International Conference on Machine Learning, PMLR 306:109269-109293, 2026.

Abstract

Understanding memorization in generative models remains challenging, with implications for copyright and privacy. Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We refer to these measurable asymmetries as the membership signal, and we study this regime for Flow Matching, which are increasingly used in deployed generative systems. We analyze the linear interpolation path $X_\lambda = (1-\lambda)X_0 + \lambda X_1$ that defines standard Flow Matching training. We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over $\lambda$, which accumulates during training, while the validation metrics remain stable. The signal has a maximum whose location we derive in closed form under Gaussian assumptions. We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied. As a proof of concept, we exploit this specific $\lambda$-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.

Cite this Paper


BibTeX
@InProceedings{pmlr-v306-sesmat26a, title = {Where Flow Matching Leaks: Characterising the Membership Signals Along the Interpolation Path}, author = {Sesmat, Thomas and Meseguer-Brocal, Gabriel and Peeters, Geoffroy}, booktitle = {Proceedings of the 43rd International Conference on Machine Learning}, pages = {109269--109293}, year = {2026}, editor = {Zhang, Tong and Dudik, Miroslav and Jaggi, Martin and Agarwal, Alekh and Li, Sharon and Schuurmans, Dale and Zhu, Jerry and Berkenkamp, Felix and Dong, Hanze and Bietti, Alberto}, volume = {306}, series = {Proceedings of Machine Learning Research}, month = {06--11 Jul}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v306/main/assets/sesmat26a/sesmat26a.pdf}, url = {https://proceedings.mlr.press/v306/sesmat26a.html}, abstract = {Understanding memorization in generative models remains challenging, with implications for copyright and privacy. Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We refer to these measurable asymmetries as the membership signal, and we study this regime for Flow Matching, which are increasingly used in deployed generative systems. We analyze the linear interpolation path $X_\lambda = (1-\lambda)X_0 + \lambda X_1$ that defines standard Flow Matching training. We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over $\lambda$, which accumulates during training, while the validation metrics remain stable. The signal has a maximum whose location we derive in closed form under Gaussian assumptions. We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied. As a proof of concept, we exploit this specific $\lambda$-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.} }
Endnote
%0 Conference Paper %T Where Flow Matching Leaks: Characterising the Membership Signals Along the Interpolation Path %A Thomas Sesmat %A Gabriel Meseguer-Brocal %A Geoffroy Peeters %B Proceedings of the 43rd International Conference on Machine Learning %C Proceedings of Machine Learning Research %D 2026 %E Tong Zhang %E Miroslav Dudik %E Martin Jaggi %E Alekh Agarwal %E Sharon Li %E Dale Schuurmans %E Jerry Zhu %E Felix Berkenkamp %E Hanze Dong %E Alberto Bietti %F pmlr-v306-sesmat26a %I PMLR %P 109269--109293 %U https://proceedings.mlr.press/v306/sesmat26a.html %V 306 %X Understanding memorization in generative models remains challenging, with implications for copyright and privacy. Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We refer to these measurable asymmetries as the membership signal, and we study this regime for Flow Matching, which are increasingly used in deployed generative systems. We analyze the linear interpolation path $X_\lambda = (1-\lambda)X_0 + \lambda X_1$ that defines standard Flow Matching training. We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over $\lambda$, which accumulates during training, while the validation metrics remain stable. The signal has a maximum whose location we derive in closed form under Gaussian assumptions. We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied. As a proof of concept, we exploit this specific $\lambda$-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.
APA
Sesmat, T., Meseguer-Brocal, G. & Peeters, G.. (2026). Where Flow Matching Leaks: Characterising the Membership Signals Along the Interpolation Path. Proceedings of the 43rd International Conference on Machine Learning, in Proceedings of Machine Learning Research 306:109269-109293 Available from https://proceedings.mlr.press/v306/sesmat26a.html.

Related Material