aidotse/LeakPro

Standardize naming for target outputs and attack signals across MIA attacks

Ouverte

#444 ouverte le 18 août 2026

 (1 commentaire) (0 réaction) (0 personne assignée)Python (26 forks)auto 404
documentationenhancementgood first issuepriority - 4

Métriques du dépôt

Stars
 (23 étoiles)
Métriques de merge PR
 (Merge moyen 68j 23h) (5 PRs mergées en 30 j)

Description

Different MIA implementations currently use different names for similar values. Examples include:

  • base: logits_target
  • attack_p: attack_signal and audit_signal
  • loss_trajectory: target
  • LiRA and MS-LiRA: taget_model_logitsm, target_signals, shadow_models_signals, and sample_target_signals

Use the same naming pattern across all similar MIA attacks. The names should make it clear whether a variable contains the model’s original output or a signal calculated from that output. For example, use target_outputs and shadow_outputs or target_model_outputs and shadow_model_outputs for original model outputs.

It might be better with outputs than logits, because LeakPro also supports regression and forecasting models, which do not necessarily produce logits.

Guide contributeur