TPR–FPR Curve (No-Auxiliary-Knowledge, CIFAR-10)
ROC-style evaluation comparing ImpMIA to leading baselines (LiRA, RMIA, Attack-R) in the No-Auxiliary-Knowledge setting.
This setting jointly removes common reference-model assumptions: (i) unknown training configuration, (ii) distribution shift in the candidate pool, and (iii) unknown member ratio.
X-axis: False positive rate (FPR, log scale). Y-axis: True positive rate (TPR, log scale). The dashed diagonal indicates random guessing.
ImpMIA achieves consistently higher TPR in the low-FPR regime, demonstrating stronger membership detection under realistic conditions where reference-model attacks degrade.