Understanding Data Importance in Machine Learning Attacks: Does Valuable Data Pose Greater Harm?
Rui Wen
Network and Distributed System Security (NDSS) Symposium 2025 · Day 2 · ML Security
Overview
In an era increasingly defined by Artificial Intelligence, the foundational role of data in driving Machine Learning (ML) innovation cannot be overstated. From large language models like ChatGPT to code generation tools like Copilot, high-quality data acts as the indispensable fuel for these sophisticated systems. However, not all data contributes equally to a model's performance or utility. Some data points are "VIPs," profoundly influencing model behavior, while others are less impactful. This talk by Rui Wen delves into a critical, yet often overlooked, aspect of ML security: the relationship between a data sample's importance and its vulnerability to various attacks, particularly Membership Inference Attacks (MIA).
Key moments
- 0:55 Defining data importance using Shapley values
- 2:40 Posing the core question: Is valuable data more vulnerable?
- 4:10 Empirical finding: High importance data is more vulnerable
- 5:50 Designing stronger attacks with importance-calibrated thresholds
- 6:40 Introducing the 'privacy on effect' on data vulnerability
- 8:40 Manipulating dataset composition to influence sample importance
Understanding Data Importance in Machine Learning Attacks: Does Valuable Data Pose Greater Harm?
Speakers: Rui Wen
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=BEqhZDdleDs
Overview
In an era increasingly defined by Artificial Intelligence, the foundational role of data in driving Machine Learning (ML) innovation cannot be overstated. From large language models like ChatGPT to code generation tools like Copilot, high-quality data acts as the indispensable fuel for these sophisticated systems. However, not all data contributes equally to a model's performance or utility. Some data points are "VIPs," profoundly influencing model behavior, while others are less impactful. This talk by Rui Wen delves into a critical, yet often overlooked, aspect of ML security: the relationship between a data sample's importance and its vulnerability to various attacks, particularly Membership Inference Attacks (MIA).
Wen's research addresses a significant gap in the current understanding of ML vulnerabilities. While much attention has historically been paid to model-centric vulnerabilities, such as those arising from overfitting, the intrinsic differences in vulnerability among individual data points within the same model have remained largely unexplored. The core question posed is whether high-value data — those samples deemed most important to a model's utility — are also inherently more susceptible to privacy breaches and other malicious manipulations. This investigation holds profound implications for real-world applications, especially in sensitive domains like medical diagnostics, where the compromise of crucial patient records could lead to severe privacy violations, discrimination, or even increased insurance premiums.
The presentation introduces a novel framework for understanding and exploiting this link. By demonstrating that data importance is directly correlated with vulnerability to MIA, Wen illustrates how this insight can be leveraged to craft more potent attacks. Furthermore, the talk explores the "privacy-on effect" in the context of data importance and showcases how actively manipulating a sample's perceived importance can make it a more vulnerable target. This work not only sheds light on a fundamental aspect of ML security but also provides actionable intelligence for both attackers seeking to refine their techniques and defenders striving to build more robust and privacy-preserving ML systems.
Background
▶ Watch: Defining data importance using Shapley values (0:55)
The rapid advancement of machine learning across diverse fields is fundamentally powered by data. It is widely acknowledged that the quantity and quality of data directly correlate with the sophistication and flexibility of the resulting ML models. However, a crucial nuance often overlooked is that the contribution of individual data points to a model's overall utility is far from uniform. Some data samples act as "VIPs," having a disproportionately high influence on the model's performance, while others contribute very little. To quantitatively measure this individual contribution, the concept of Shapley value is employed. Originating from cooperative game theory, the Shapley value assigns a fair share of the total gain to each player in a coalition. In the context of ML, it quantifies how much an individual training sample contributes to a model's performance, providing a robust metric for data importance. A sample with a high Shapley value is considered "important data," indicating its significant positive impact on model utility, whereas a low Shapley value denotes a "less important" sample.
Prior research in ML security has predominantly focused on model-level vulnerabilities. For instance, discussions around overfitted models being more susceptible to attacks like Membership Inference Attacks (MIA) are common. However, even within a single, trained model, individual data samples exhibit varying degrees of vulnerability. The talk highlights that despite being members of the training dataset, some samples are significantly more vulnerable to MIA than others. This observation raises a fundamental question: Can data importance explain these disparities in vulnerability? Specifically, are the high-value, "VIP" data samples also the ones most prone to privacy breaches and other attacks?
To address this, the research utilizes Membership Inference Attacks (MIA) as a primary case study. MIA is a type of privacy attack where an adversary attempts to determine whether a specific data sample was part of the dataset used to train a target machine learning model. This attack poses a significant threat to data privacy, especially when models are trained on sensitive personal information, such as medical records or financial data. If successful, MIA can reveal private attributes about individuals, leading to various harms including discrimination, targeted attacks, or the erosion of trust in AI systems. The existing challenge lies in the fact that current MIA techniques often treat all training data points uniformly, failing to account for the intrinsic differences in their contribution and, consequently, their inherent vulnerability.
Key Findings
▶ Watch: Empirical finding: High importance data is more vulnerable (4:10)
Rui Wen's research uncovers several critical findings that illuminate the intricate relationship between data importance and vulnerability in machine learning models, particularly concerning Membership Inference Attacks. These discoveries not only deepen our theoretical understanding but also provide practical avenues for both enhancing and defending against ML attacks.
- High Importance Data is More Vulnerable to Membership Inference Attacks: The primary and most significant finding is a direct correlation between a data sample's importance (quantified by its Shapley value) and its susceptibility to Membership Inference Attacks. Experiments demonstrated that samples contributing more significantly to the model's utility are markedly more vulnerable to being identified as members of the training dataset compared to less important samples. This was shown by sorting training data by importance and running MIAs on subsets, consistently revealing higher attack success rates on more important data.
- Data Importance Can Be Leveraged to Design Stronger Attacks: Building on the first finding, the research shows that incorporating data importance into attack methodologies can significantly enhance their effectiveness. Traditional loss-based MIAs often struggle with certain members (low importance, high loss) and non-members (high importance, low loss). By introducing sample-specific thresholds or an importance-related factor to calibrate membership metrics, attackers can more accurately differentiate between members and non-members. This "importance calibration" leads to a demonstrably better performance for Membership Inference Attacks.
- The "Privacy-On Effect" Extends to Data Importance: The study confirms that the privacy-on effect, previously observed in data vulnerability where removing the most vulnerable data makes other data points more vulnerable, also manifests in the domain of data importance. When the most important samples are removed from a dataset, previously less important samples start to gain importance. A controlled experiment, which involved removing either the most or least important samples, solidified this conclusion, demonstrating that the shift in importance is not merely a consequence of dataset size reduction but an intrinsic effect.
- Active Manipulation of Data Importance is Feasible and Boosts Vulnerability: Perhaps one of the most concerning findings for defenders is the demonstration that an attacker can actively manipulate the importance of a target sample, thereby making it more vulnerable to inference attacks. By employing a "sneaky approach" — specifically, duplicating a target sample multiple times with consistently incorrect labels — the research shows that these samples can be made to appear as outliers, grabbing the model's attention and significantly boosting their Shapley value (importance). This manipulation directly translates to increased vulnerability, offering a powerful tool for crafting advanced attacks, including variants of membership poisoning attacks.
Technical Deep Dive
▶ Watch: Designing stronger attacks with importance-calibrated thresholds (5:50)
The technical core of Rui Wen's presentation revolves around the quantitative measurement of data importance using Shapley value and its subsequent application to understand and exploit vulnerabilities in machine learning models. The Shapley value, a concept from cooperative game theory, provides a principled way to attribute the contribution of each player (in this case, each data sample) to the overall outcome (model utility or performance). For a given model and dataset, the Shapley value of a data point is calculated by averaging its marginal contribution to all possible subsets of the dataset. This means considering how much the model's performance improves when that specific data point is added to various training subsets. The higher the Shapley value, the more crucial that data point is for the model's performance. The speaker notes that among various methods for evaluating importance, the Shapley value-based approach yielded the most significant performance gap when comparing models trained on high vs. low importance data, making it the preferred metric.
To establish the link between data importance and vulnerability, a multi-step experimental methodology was employed, focusing on Membership Inference Attacks (MIA):
- Target Model Training: An initial machine learning model is trained on a complete dataset.
- Data Importance Scoring: The training dataset is then sorted by the Shapley value of each sample, effectively ranking them by their contribution to the trained model.
- MIA on Subsets: Membership inference attacks are subsequently run on different subsets of the training data, categorized by their level of importance (e.g., top 10% most important, bottom 10% least important, etc.).
The results consistently showed that samples with higher Shapley values (higher importance) were significantly more vulnerable to MIA. This indicates that the model "remembers" or relies more heavily on these crucial data points, making their presence in the training set easier to infer.
The findings also paved the way for designing stronger Membership Inference Attacks. A common, simple MIA technique relies on the observation that member samples typically incur lower loss values during training compared to non-member samples. An attacker might set a fixed loss threshold, classifying any sample with a loss below it as a member. However, this method has limitations:
- Low-importance members: Some members, being less important or "hard to learn," might still have relatively high loss, making them difficult to distinguish from non-members.
- High-importance non-members: Conversely, some non-members, if easily learnable or highly representative of the data distribution, might exhibit low loss, potentially being misclassified as members.
To overcome these challenges, the research proposes an importance calibration strategy. Instead of a uniform threshold, the idea is to introduce sample-specific thresholds based on importance. For example, a high-importance sample would be compared against a threshold derived from other high-importance samples, and similarly for low-importance samples. While maintaining a consistent threshold across the dataset for integration into existing frameworks, the speaker suggests "tweaking the membership metrics" by introducing an importance-related factor. This factor would effectively adjust the observed loss or other membership metric of a sample based on its importance, allowing for a more nuanced and accurate determination of membership status. The experimental results confirmed that this importance-calibrated MIA achieved better performance compared to uncalibrated methods.
Further extending the analysis, the talk investigated the privacy-on effect within the context of data importance. This effect describes a scenario where efforts to enhance privacy by removing highly vulnerable data points inadvertently increase the vulnerability of the remaining, previously safer data. To test this for importance, the researchers performed an experiment:
- A model was trained, and data importance was calculated.
- The most important samples were removed from the dataset.
- The model was retrained on the reduced dataset, and importance was recalculated for the remaining samples.
The findings indicated that previously less important samples started gaining importance after the removal of the most important ones. To ensure this shift wasn't merely due to the change in dataset size, a controlled experiment was conducted where either the most or least important samples were removed. The conclusion held: removing the most important samples consistently led to an increase in importance for previously less important data.
Demo / Proof of Concept
▶ Watch: Introducing the 'privacy on effect' on data vulnerability (6:40)
The most compelling demonstration within the talk focused on the active manipulation of data importance to make specific target samples more vulnerable to attacks. This proof-of-concept illustrates a sophisticated attack vector that could be exploited by adversaries.
The core idea is to take a sample that is initially of low importance and "boost" its importance, thereby making it an easier target for Membership Inference Attacks. Since there's no direct, uniform framework for arbitrarily increasing a sample's Shapley value, the researchers employed a creative, ad hoc method that leverages how models learn and identify outliers.
The "sneaky approach" involved the following steps:
- Target Selection: Identify a specific data sample (marked with a black square in the presentation's illustrative figures) whose importance is to be increased.
- Duplication with Incorrect Labels: The chosen target sample was duplicated multiple times, but crucially, each duplicate was assigned a consistently incorrect label. For example, if the original sample was an image of a cat labeled "cat," the duplicates would be the same image but labeled "dog."
- Mechanism of Importance Boost: The rationale behind this strategy is that when a machine learning model encounters numerous instances of the same input (the target sample) but with conflicting and incorrect labels, it begins to treat this sample as an outlier or a confusing data point. Outliers tend to "grab the model's attention" more significantly during the training process. The model struggles to correctly learn from these contradictory examples, causing it to expend more "effort" on them. This increased "attention" or "effort" translates directly into a higher contribution to the model's overall utility, thus boosting its calculated Shapley value and, consequently, its importance.
To empirically validate this concept, an experiment was conducted:
- Sample Duplication: 50 randomly selected samples were duplicated 16 times each.
- Recalculation of Importance: The Shapley values for all samples in the dataset (both the manipulated 50 and the untouched ones) were recalculated after the duplication process.
The results were striking:
- Significant Importance Gain: 45 out of the 50 manipulated samples showed a substantial gain in importance, with an impressive average increase of 53% in their Shapley values.
- Minimal Impact on Untouched Samples: Crucially, the importance of the untouched samples in the dataset was barely influenced, demonstrating the targeted nature of this manipulation.
The speaker explicitly links this method to a classic membership poisoning attack, referencing prior work by Tmorto. This connection highlights that actively manipulating a target sample's importance, by making it an outlier through label inconsistencies, is not just a theoretical concept but a powerful practical tool for crafting stronger, more targeted attacks that exploit the model's learning process to increase a sample's vulnerability.
Defensive Implications
▶ Watch: Manipulating dataset composition to influence sample importance (8:40)
The findings presented by Rui Wen carry significant implications for the defense of machine learning systems against privacy breaches and adversarial manipulations. Understanding the intricate link between data importance and vulnerability provides defenders with novel perspectives and actionable strategies.
Firstly, the revelation that high-importance data is more vulnerable mandates a shift in how organizations prioritize data protection. Instead of a uniform approach, sensitive or critical data points identified as having high Shapley values should be afforded heightened security measures. This could involve applying stronger privacy-preserving machine learning (PPML) techniques, such as differential privacy, more aggressively to these specific data subsets during model training. For example, in medical diagnostics, patient records with rare but crucial symptoms that significantly impact model accuracy would be identified as high-importance. These records, being more vulnerable to MIA, would then necessitate more stringent anonymization or noise injection strategies.
Secondly, the ability of attackers to leverage data importance to design stronger Membership Inference Attacks underscores the need for more sophisticated MIA detection and mitigation mechanisms. Defenders should explore implementing importance-aware monitoring systems that can detect unusual patterns in loss values or other membership metrics, especially when correlated with the importance profiles of data samples. Furthermore, research into importance-calibrated defenses could be valuable, where the model's robustness or privacy guarantees are adaptively adjusted based on the importance of the data it processes.
Thirdly, the observation of the privacy-on effect in data importance highlights a subtle but critical challenge for data sanitization efforts. Simply removing "vulnerable" or "important" data to enhance privacy might inadvertently shift importance and vulnerability to other, previously safer, data points. Defenders must consider the dynamic nature of importance and vulnerability when curating datasets or implementing data redaction policies. A holistic approach that re-evaluates the privacy landscape after data modifications is crucial to avoid unintended consequences.
Finally, the demonstration that attackers can actively manipulate data importance through techniques like duplicating samples with incorrect labels (a form of membership poisoning) presents a new frontier for adversarial robustness. Organizations must develop mechanisms to detect such manipulations within their training datasets. This could involve data integrity checks, anomaly detection algorithms that flag unusual patterns of duplicate or mislabeled data, or data provenance tracking to identify suspicious data injection. Robust training procedures that are less susceptible to the influence of outliers or conflicting labels are also paramount. Ultimately, defenders should integrate the concept of data importance as a critical metric in their risk assessment frameworks, moving beyond simply identifying sensitive data to understanding its specific contribution and corresponding vulnerability within the ML ecosystem. This proactive approach will be essential in building more resilient and privacy-respecting AI systems.
Key Takeaways
- Direct Link: There is a clear and direct correlation between a data sample's importance (quantified by its Shapley value) and its vulnerability to Membership Inference Attacks (MIA). High-importance data is significantly more susceptible to privacy breaches.
- Stronger Attacks: Understanding data importance allows attackers to craft more potent MIAs. By using importance calibration or sample-specific thresholds, they can more accurately infer membership, improving attack performance.
- Dynamic Vulnerability: The privacy-on effect extends to data importance, meaning that removing highly important data can cause previously less important data to gain importance and thus become more vulnerable.
- Active Manipulation: Attackers can actively manipulate the importance of target data samples, for instance, by duplicating them with consistently incorrect labels. This technique effectively boosts a sample's Shapley value and makes it more vulnerable to inference attacks, akin to membership poisoning.
- Prioritized Defense: Defenders must prioritize the protection of high-importance data. This necessitates tailored privacy-preserving ML (PPML) strategies and enhanced security measures for data points identified as critical to model utility.
- Enhanced Monitoring: Organizations should implement importance-aware monitoring and data integrity checks to detect both unusual patterns in data vulnerability and active attempts to manipulate data importance within training datasets.
About the Speaker(s)
Rui Wen is the presenter of this talk, which is a joint work with Michael and Yang. The transcript indicates Rui Wen's expertise in machine learning security, particularly in understanding the nuances of data's role in vulnerabilities and attacks. No specific institutional affiliation or title is provided in the transcript or metadata.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Solid academic ML security research with a clean central thesis: data importance (Shapley value) correlates with MIA vulnerability, and that correlation can be weaponized. The work is methodologically sound and the active manipulation angle is the most interesting piece, but this is primarily an incremental contribution to a well-traveled space rather than a paradigm shift.
Heather Calloway (CISO) — WEAK
Technically credible research on the relationship between data importance and ML privacy vulnerability, but it stops well short of the governance and operational questions that would make it matter to security leaders. The defensive implications section reads like a literature review, not a decision brief.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025