Auditing the Privacy of Synthetic Gene Expression Data: A Unified Weighted-Distance Framework for No-Box Membership Inference

📅 2026-10-02
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the privacy leakage risks posed by membership inference attacks on synthetic gene expression data. Leveraging TCGA data, it proposes a unified weighted distance framework that integrates five black-box attacks to evaluate the privacy security of data generated by conditional variational autoencoders. The work innovatively introduces spectral residualization to eliminate principal component interference, thereby enhancing detection sensitivity, and further optimizes attack strategies by incorporating Kullback-Leibler divergence alongside biological pathway priors. Experimental results demonstrate that spectral residualization improves the AUC to 0.8951 and significantly increases the true positive rate under low false positive conditions. These findings validate the effectiveness of specific weighting strategies for privacy risk assessment in genomic data.
📝 Abstract
Synthetic gene expression data is increasingly proposed as a privacy-preserving substitute for controlled-access genomic repositories, but its safety depends on empirical auditing. Membership inference attacks (MIAs) provide that audit by testing whether a patient's gene expression profile was used to train a generative model. We report a red-team study on synthetic gene expression data derived from bulk RNA-seq profiles in The Cancer Genome Atlas, released by the ELSA Health 2026 Challenge. We unify five no-box attacks under a single weighted-distance framework in which each variant differs only in how it weights genes: uniformly (baseline), by variance, by synthetic-versus-reference KL divergence, by spectral residualization removing dominant principal components, and by curated pathway membership. Against a conditional variational autoencoder, spectral residualization raises AUC from 0.8251 to 0.8951 and TPR at 1% FPR from 0.3842 to 0.5970 on pan-cancer TCGA. Biological pathway priors did not transfer across targets.
Problem

Research questions and friction points this paper is trying to address.

Synthetic gene expression data
Privacy auditing
Membership inference attacks
No-box attacks
Generative models
Innovation

Methods, ideas, or system contributions that make the work stand out.

Membership Inference Attack
No-Box Attack
Weighted-Distance Framework
Spectral Residualization
Synthetic Gene Expression
🔎 Similar Papers
No similar papers found.