---
title: "Membership inference"
description: "An attack that determines whether a specific person's record was in a model's training set from the model's behaviour."
canonical: https://aigovernanceengineer.com/glossary/membership-inference
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-24
---

# Membership inference

An attack that determines whether a specific person's record was in a model's training set from the model's behaviour [1]. The EDPB counts resistance to it among the evidence for claiming a model is anonymous.

- Developed in: [ch. 19, AI-specific privacy breaches](https://aigovernanceengineer.com/bok/privacy-and-ai#ai-specific-privacy-breaches)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- Contrast with: [Model inversion](https://aigovernanceengineer.com/glossary/model-inversion)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-membership-inference

## Sources

[1] "Membership Inference Attacks against Machine Learning Models" (Shokri et al.; arXiv 1610.05820). arXiv. 2016-10-18. https://arxiv.org/abs/1610.05820 (verified: primary)
