Effect of Assumption Removal
Performance of the best prior method (LiRA) and our method (ImpMIA) under the progressive removal of assumptions on CINIC-10.
Y-axis: TPR at 0% FPR. X-axis: assumptions removed in sequence — Known training configuration → Matched non-member distribution → Known member ratio → All removed.
As assumptions are removed, LiRA performance drops sharply, while ImpMIA remains stable, showing minimal dependence on these assumptions.