aidotse/LeakPro
Standardize naming for target outputs and attack signals across MIA attacks
Aberta
#444 aberto em 18 de ago. de 2026
documentationenhancementgood first issuepriority - 4
Métricas do repositório
- Stars
- (23 estrelas)
- Métricas de merge de PR
- (Mesclagem média 68d 23h) (5 fundiu PRs em 30d)
Description
Different MIA implementations currently use different names for similar values. Examples include:
- base: logits_target
- attack_p: attack_signal and audit_signal
- loss_trajectory: target
- LiRA and MS-LiRA: taget_model_logitsm, target_signals, shadow_models_signals, and sample_target_signals
Use the same naming pattern across all similar MIA attacks.
The names should make it clear whether a variable contains the model’s original output or a signal calculated from that output.
For example, use target_outputs and shadow_outputs or target_model_outputs and shadow_model_outputs for original model outputs.
It might be better with outputs than logits, because LeakPro also supports regression and forecasting models, which do not necessarily produce logits.