Generalizability of spectral privacy-risk relationships

Determine whether the observed relationships between WeightWatcher spectral metrics and LiRA privacy risk extend to larger, more complex architectures, including ResNets and Transformers, and across more diverse data modalities, including text.

Background

The paper evaluates the relationship between neural-network weight spectral metrics and membership-inference vulnerability using only multilayer perceptrons trained on CIFAR-10 and the Volkert tabular dataset. The principal findings concern associations between stable rank or Log α-Norm and the performance of the LiRA attack.

Because the experiments are restricted to two datasets, one model family, and limited data modalities, the authors explicitly leave unresolved whether these associations are general properties of neural-network spectra or are specific to the experimental setting. Establishing their applicability to larger architectures such as ResNets and Transformers and to modalities such as text would test the broader validity of spectral metrics as data-free indicators of privacy risk.

References

Although these datasets provide complementary domains and CIFAR-10 is one of the most widely used benchmarks in MIA research~\citep{Hu:2022}, it remains unclear whether the observed relationships extend to larger, more complex architectures (e.g., ResNets and Transformers) or across more diverse data modalities (e.g., text).

Predicting Privacy Leakage from Weight Spectral Density  (2609.11780 - Preen et al., 10 Sep 2026) in Section 6, Conclusions and Limitations, paragraph 'Limitations'