A healthcare organization uses a machine learning model to predict patient readmission risk. The model was trained on a dataset that includes sensitive patient information. During a security review, the team wants to verify that an attacker cannot determine whether a specific patient's record was part of the training set by querying the model. Which of the following should the team perform to directly assess this risk?
A membership inference attack simulation directly tests whether an attacker can infer if a particular record was in the training set. By mimicking an adversary's queries and analyzing confidence scores, the team can measure the model's vulnerability. This is the most direct method to assess the specific risk described in the scenario.
Why this answer
Membership inference attacks specifically aim to determine if a data point was used during training. Simulating such an attack allows the team to empirically measure the model's susceptibility. Model inversion, k-anonymity, and SHAP values address different aspects of privacy or interpretability and do not directly evaluate the risk of membership inference.
Exam trap
The trap here is conflating model inversion with membership inference, as both are privacy attacks but target different information.