IDEAS home Printed from https://ideas.repec.org/a/gam/jmathe/v13y2025i19p3070-d1756967.html
   My bibliography  Save this article

Mitigating Membership Inference Attacks via Generative Denoising Mechanisms

Author

Listed:
  • Zhijie Yang

    (College of Mechatronic Engineering, North University of China, No. 3 Xueyuan Road, Taiyuan 030051, China)

  • Xiaolong Yan

    (College of Mechatronic Engineering, North University of China, No. 3 Xueyuan Road, Taiyuan 030051, China)

  • Guoguang Chen

    (College of Mechatronic Engineering, North University of China, No. 3 Xueyuan Road, Taiyuan 030051, China)

  • Xiaoli Tian

    (College of Mechatronic Engineering, North University of China, No. 3 Xueyuan Road, Taiyuan 030051, China)

Abstract

Membership Inference Attacks (MIAs) pose a significant threat to privacy in modern machine learning systems, enabling adversaries to determine whether a specific data record was used during model training. Existing defense techniques often degrade model utility or rely on heuristic noise injection, which fails to provide a robust, mathematically grounded defense. In this paper, we propose Diffusion-Driven Data Preprocessing (D 3 P), a novel privacy-preserving framework leveraging generative diffusion models to transform sensitive training data before learning, thereby reducing the susceptibility of trained models to MIAs. Our method integrates a mathematically rigorous denoising process into a privacy-oriented diffusion pipeline, which ensures that the reconstructed data maintains essential semantic features for model utility while obfuscating fine-grained patterns that MIAs exploit. We further introduce a privacy–utility optimization strategy grounded in formal probabilistic analysis, enabling adaptive control of the diffusion noise schedule to balance attack resilience and predictive performance. Experimental evaluations across multiple datasets and architectures demonstrate that D 3 P significantly reduces MIA success rates by up to 42.3 % compared to state-of-the-art defenses, with a less than 2.5 % loss in accuracy. This work provides a theoretically principled and empirically validated pathway for integrating diffusion-based generative mechanisms into privacy-preserving AI pipelines, which is particularly suitable for deployment in cloud-based and blockchain-enabled machine learning environments.

Suggested Citation

  • Zhijie Yang & Xiaolong Yan & Guoguang Chen & Xiaoli Tian, 2025. "Mitigating Membership Inference Attacks via Generative Denoising Mechanisms," Mathematics, MDPI, vol. 13(19), pages 1-25, September.
  • Handle: RePEc:gam:jmathe:v:13:y:2025:i:19:p:3070-:d:1756967
    as

    Download full text from publisher

    File URL: https://www.mdpi.com/2227-7390/13/19/3070/pdf
    Download Restriction: no

    File URL: https://www.mdpi.com/2227-7390/13/19/3070/
    Download Restriction: no
    ---><---

    More about this item

    Keywords

    ;
    ;
    ;
    ;

    Statistics

    Access and download statistics

    Corrections

    All material on this site has been provided by the respective publishers and authors. You can help correct errors and omissions. When requesting a correction, please mention this item's handle: RePEc:gam:jmathe:v:13:y:2025:i:19:p:3070-:d:1756967. See general information about how to correct material in RePEc.

    If you have authored this item and are not yet registered with RePEc, we encourage you to do it here. This allows to link your profile to this item. It also allows you to accept potential citations to this item that we are uncertain about.

    We have no bibliographic references for this item. You can help adding them by using this form .

    If you know of missing items citing this one, you can help us creating those links by adding the relevant references in the same way as above, for each refering item. If you are a registered author of this item, you may also want to check the "citations" tab in your RePEc Author Service profile, as there may be some citations waiting for confirmation.

    For technical questions regarding this item, or to correct its authors, title, abstract, bibliographic or download information, contact: MDPI Indexing Manager (email available below). General contact details of provider: https://www.mdpi.com .

    Please note that corrections may take a couple of weeks to filter through the various RePEc services.

    IDEAS is a RePEc service. RePEc uses bibliographic data supplied by the respective publishers.