跳到正文
原文
arXiv:cs.LG(机器学习,全量分类)· Sushovan Majhi, Pramita Bagchi·· 14 小时前AI 评分50

arXiv 论文提出生成模型记忆化的精确零假设检验方法

The Null Is the Hard Part: Exact Tests for Memorization in Generative Models

AI 导读

Sushovan Majhi 与 Pramita Bagchi 在 arXiv 论文(2610.00251)中指出,现有生成模型记忆化审计缺少零假设分布,结论可能出错。

正文

View PDF HTML (experimental)

Abstract:Memorization audits of generative models read similarity scores against thresholds, with no null distribution, and the conclusions they support can be wrong. By MemBench's rule, the benchmark's mitigations roughly halve Stable Diffusion's memorization; audited with false-discovery control, two thirds of the certified images are no longer detected under random prompt perturbations, five sixths under attention rescaling, and all of them under embedding optimization. The field's data-copying test, read against its own null, flags ten of twenty-four generators that reproduce nothing. We argue that for memorization the null is the hard part, and supply two. For a whole model, training and held-out images are exchangeable given its samples, and relabelling them is a permutation test, exact for any statistic when the held-out images are a random split; under it, a nearest-neighbour preference still fires on seven of those twenty-four, and a count restricted to the near-duplicate scale on none (McNemar p=0.016). For single images, the natural nulls fail twice, measurably: ranking an image among random images yields 596 false discoveries among 2,365 controls, and resampling independent generations makes the null three times too narrow. Calibrated against matched controls, the audit certifies 36 of 61 MemBench images at 5% false-discovery rate, held-out controls are certified in 0.01% of calibration splits, and on this benchmark two generations per image recover that count. A calibrated maximum, which reads occasional rather than typical copying, certifies 46. As the scale-restricted statistic we recommend the small-scale mass of the Intersection Euler Characteristic Profile, which also counts distinct images copied and tests whether two models copy the same ones.
Comments: 23 pages, 5 figures. Code and measurement outputs at this https URL
Subjects: Machine Learning (cs.LG)
MSC classes: 62G10, 62G09, 55N31, 68T07
ACM classes: I.2.6; G.3; I.5.1
Cite as: arXiv:2610.00251 [cs.LG]
  (or arXiv:2610.00251v1 [cs.LG] for this version)
  https://doi.org/10.48550/arXiv.2610.00251

arXiv-issued DOI via DataCite (pending registration)

Submission history

From: Sushovan Majhi [view email]
[v1] Wed, 23 Sep 2026 17:59:25 UTC (380 KB)

来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org