arXiv · 2501.11786
Synthetic Data Can Mislead Evaluations: Membership Inference as Machine Text Detection
Abstract
Recent work shows membership inference attacks (MIAs) on large language models (LLMs) produce inconclusive results, partly due to difficulties in creating non-member datasets without temporal shifts. While researchers have turned to synthetic data as an alternative, we show this approach can be fundamentally misleading. Our experiments indicate that MIAs function as machine-generated text detectors, incorrectly identifying synthetic data as training samples regardless of the data source. This behavior persists across different model architectures and sizes, from open-source models to commercial ones such as GPT-3.5. Even synthetic text generated by different, potentially larger models is classified as training data by the target model. Our findings highlight a serious concern: using synthetic data in membership evaluations may lead to false conclusions about model memorization and data leakage. We caution that this issue could affect other evaluations using model signals such as loss where synthetic or machine-generated translated data substitutes for real-world samples.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Ali Naseh, Niloofar Mireshghallah. 2025-01-20. Synthetic Data Can Mislead Evaluations: Membership Inference as Machine Text Detection. https://arxiv.org/abs/2501.11786
Cite the original work for its findings. Save a collection to share your selection of sources.