MEGA Hub

MemCatalyst: Amplifying Data Auditing on Vision-Language Models via Data Poisoning

Authors

Do you know Xukun Luan?You can claim authorship or link another user.Do you know Jinyan Liu?You can claim authorship or link another user.Do you know Yuhui Gong?You can claim authorship or link another user.Do you know Yuanguo Bi?You can claim authorship or link another user.Do you know Bing Hu?You can claim authorship or link another user.Do you know Xuesong Li?You can claim authorship or link another user.Do you know Di Wang?You can claim authorship or link another user.

Abstract

Vision-Language models (VLMs) achieve outstanding performance largely due to the amount of training data available on the internet. At the same time, data holders (e.g., artists) urgently need to determine whether their data has been used for model training without authorization, which concerns both intellectual property rights and personal privacy. Data auditing, particularly through membership inference (MI), has attracted attention as a direct tool. This work proposes MemCatalyst, a set of data poisoning tools, aiming to amplify the data auditing performance on VLMs. MemCatalyst employs two strategies: Poisoning Text (PT) and Poisoning Image (PI). MemCatalyst forces VLMs to over-learn specific inconsistencies between image features and textual semantics during training, thereby increasing their susceptibility to membership information auditing. Crucially, the transferability of poisoned samples across different VLM architectures is demonstrated to be effective in the black-box setting. Extensive evaluations using five state-of-the-art data audits on two prominent VLMs demonstrate that MemCatalyst markedly enhances MI AUC scores with a minimal budget of poisoned samples, while maintaining a negligible impact on model performance.

Community

00