The sharing of sensitive network flow data is heavily restricted due to privacy risks, which limits its use in tasks such as traffic analysis, anomaly detection, and the training of machine learning models. A common workaround is to release synthetic flow records, produced by a generative model trained on the original real flows. However, generative models often lack formal privacy guarantees and can inadvertently memorize specific training patterns, creating identifiable signatures that compromise the privacy. To address this, this work proposes FlowMIA, a black-box auditing framework that quantifies this training-set leakage risk for network-flow generators. FlowMIA applies three Membership Inference Attacks (MIAs) against a trained generator. The adversary is modeled as an external party that holds only the synthetic dataset and reference samples from the same domain. FlowMIA reports the resulting leakage together with fidelity and utility. We used FlowMIA to audit generative models based on Generative Adversarial Networks (CTGAN and NetShare) and Large Language Models (Tabula), which revealed that high-fidelity models are susceptible to increased vulnerability. The results demonstrate that this three-way trade-off between privacy, fidelity, and utility remains the primary challenge for the secure sharing of network traffic data.
FlowMIA: Membership Inference Attack on Generative Network Flow Models
Drago I.;
2026-01-01
Abstract
The sharing of sensitive network flow data is heavily restricted due to privacy risks, which limits its use in tasks such as traffic analysis, anomaly detection, and the training of machine learning models. A common workaround is to release synthetic flow records, produced by a generative model trained on the original real flows. However, generative models often lack formal privacy guarantees and can inadvertently memorize specific training patterns, creating identifiable signatures that compromise the privacy. To address this, this work proposes FlowMIA, a black-box auditing framework that quantifies this training-set leakage risk for network-flow generators. FlowMIA applies three Membership Inference Attacks (MIAs) against a trained generator. The adversary is modeled as an external party that holds only the synthetic dataset and reference samples from the same domain. FlowMIA reports the resulting leakage together with fidelity and utility. We used FlowMIA to audit generative models based on Generative Adversarial Networks (CTGAN and NetShare) and Large Language Models (Tabula), which revealed that high-fidelity models are susceptible to increased vulnerability. The results demonstrate that this three-way trade-off between privacy, fidelity, and utility remains the primary challenge for the secure sharing of network traffic data.| File | Dimensione | Formato | |
|---|---|---|---|
|
IEEE___DCOSS_2026___Urbcom___Guilherme.pdf
Accesso aperto
Tipo di file:
POSTPRINT (VERSIONE FINALE DELL’AUTORE)
Dimensione
318.16 kB
Formato
Adobe PDF
|
318.16 kB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.



