aidotse/LeakPro

Standardize naming for target outputs and attack signals across MIA attacks

Aperta

#444 aperta il 18 ago 2026

 (1 commento) (0 reazioni) (0 assegnatari)Python (26 fork)auto 404
documentationenhancementgood first issuepriority - 4

Metriche repository

Star
 (23 stelle)
Metriche merge PR
 (Merge medio 68g 23h) (5 PR mergiate in 30 g)

Descrizione

Different MIA implementations currently use different names for similar values. Examples include:

  • base: logits_target
  • attack_p: attack_signal and audit_signal
  • loss_trajectory: target
  • LiRA and MS-LiRA: taget_model_logitsm, target_signals, shadow_models_signals, and sample_target_signals

Use the same naming pattern across all similar MIA attacks. The names should make it clear whether a variable contains the model’s original output or a signal calculated from that output. For example, use target_outputs and shadow_outputs or target_model_outputs and shadow_model_outputs for original model outputs.

It might be better with outputs than logits, because LeakPro also supports regression and forecasting models, which do not necessarily produce logits.

Guida contributor