5
0

Frequency-Calibrated Membership Inference Attacks on Medical Image Diffusion Models

Xinkai Zhao
Yuta Tokuoka
Junichiro Iwasawa
Keita Oda
Main:8 Pages
2 Figures
Bibliography:2 Pages
3 Tables
Abstract

The increasing use of diffusion models for image generation, especially in sensitive areas like medical imaging, has raised significant privacy concerns. Membership Inference Attack (MIA) has emerged as a potential approach to determine if a specific image was used to train a diffusion model, thus quantifying privacy risks. Existing MIA methods often rely on diffusion reconstruction errors, where member images are expected to have lower reconstruction errors than non-member images. However, applying these methods directly to medical images faces challenges. Reconstruction error is influenced by inherent image difficulty, and diffusion models struggle with high-frequency detail reconstruction. To address these issues, we propose a Frequency-Calibrated Reconstruction Error (FCRE) method for MIAs on medical image diffusion models. By focusing on reconstruction errors within a specific mid-frequency range and excluding both high-frequency (difficult to reconstruct) and low-frequency (less informative) regions, our frequency-selective approach mitigates the confounding factor of inherent image difficulty. Specifically, we analyze the reverse diffusion process, obtain the mid-frequency reconstruction error, and compute the structural similarity index score between the reconstructed and original images. Membership is determined by comparing this score to a threshold. Experiments on several medical image datasets demonstrate that our FCRE method outperforms existing MIA methods.

View on arXiv
@article{zhao2025_2506.14919,
  title={ Frequency-Calibrated Membership Inference Attacks on Medical Image Diffusion Models },
  author={ Xinkai Zhao and Yuta Tokuoka and Junichiro Iwasawa and Keita Oda },
  journal={arXiv preprint arXiv:2506.14919},
  year={ 2025 }
}
Comments on this paper