Good Papers

Membership Inference on Synthetic Single-Cell Genomic Data

Membership inference attacks successfully identify training donors in synthetic single-cell RNA-seq data, revealing that leading generation methods inadequately protect privacy and leak more as donor counts drop.

Steven Golob, Patrick McKeever, Sikha Pentyala, Martine De Cock, Jonathan Peck

Published 2026Paris Poster Session 2 · Wed, Dec 9, 5:00 PM–7:00 PM local time · Paris Poster HallOpenReview ↗

83%
OverallMust read
?
OverallMust readVote to see the scoreThe exact score shows once you've voted, so every vote is your own call. The first half of each home page shelf shows its scores.
Readers
–

Only vote on papers you've read. Sign in with GitHub to vote.

AI panel13/20reviewers recommend it
lenient 5/5
medium 7/10
strict 1/5
AI panel?Vote to see what the 20 AI reviewers said

Abstract

Abstract Single-cell RNA sequencing (scRNA-seq) data is subject to strict access control due to its sensitive nature, motivating the use of synthetic data generation (SDG) for privacy-preserving data sharing. We present the first adversarial privacy attack that performs meaningfully above random guessing against state-of-the-art scRNA-seq SDG methods. Our attack enables donor-level membership inference, demonstrating that leading SDG techniques fail to adequately mask which individuals were used to train the generator. We show that privacy leakage increases as the number of training donors decreases. Although the attack is designed to exploit vulnerabilities in scDesign2, we find that it also succeeds against synthetic data generated by other leading methods, including scDesign3 and scVI. This transferability indicates that an adversary can infer sensitive information from synthetic data without access to the training procedure, model parameters, or even the underlying generation algorithm. Finally, we investigate the use of perturbation with noise during the SDG process as a first-line defense, empirically evaluating its effectiveness in neutralizing the attack and its impact on utility.