All methods
MIA
Daubert-eligibleTier 1

Min-K%++

Zhang et al. · ICLR 2025

Overview

Calibrated membership-inference attack against pretraining data. Uses per-token log-likelihood vs. neighborhood entropy to achieve state-of-the-art AUROC across LLaMA, Pythia, GPT-NeoX families. Decouples token informativeness from membership signal, producing a clean p-value under permutation null.

Evidentiary posture

Method is peer-reviewed, has published error rates in the literature, and is reproducible from the chain-of-custody record. Eligible for Tier-A evidentiary packaging under the Daubert / FRE 702 framework. Admission in any specific case remains the court's determination.

Technical parameters, adversarial-robustness bounds, and reference implementation are disclosed to counsel and opposing experts under MNDA.