TY - GEN
T1 - Feature Masking Isn't Enough
T2 - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026
AU - Oren, Elran
AU - Hersko, Ido
AU - Cahana, Yitschak
AU - Shabtai, Asaf
AU - Elovici, Yuval
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026/1/1
Y1 - 2026/1/1
N2 - Feature masking, the practice of withholding sensitive attributes from potential adversaries, is widely relied upon as a frontline defense against privacy attacks on tabular machine learning (ML) models. However, this paper demonstrates that the protection it offers is an illusion. While traditional Membership Inference Attacks (MIAs) assume adversaries possess complete knowledge of a target's features, we formalize a highly realistic threat model where attackers observe only partial records. To exploit this, we introduce the Missing Features-Membership Inference Attack (MF-MIA), a practical two-stage black-box framework. MF-MIA first imputes with-held attributes using auxiliary data with overlapping features, and subsequently mounts a shadow-model-based MIA on the completed queries. In a cross-database case study (target model trained on the General Social Survey; auxiliary data from UCI Adult), MF-MIA achieves up to 59.3% membership accuracy even when a sensitive feature is entirely withheld. By benchmarking multiple completion strategies, including statistical priors, model-based imputation, TVAE, and masked autoencoders, we show that attack power scales with imputation quality, independent of target-model feature importance. Finally, we demonstrate that Large Language Models (LLMs) can effectively substitute for tabular auxiliary data in data-scarce environments, decisively proving that feature masking cannot stand alone as a robust privacy defense.
AB - Feature masking, the practice of withholding sensitive attributes from potential adversaries, is widely relied upon as a frontline defense against privacy attacks on tabular machine learning (ML) models. However, this paper demonstrates that the protection it offers is an illusion. While traditional Membership Inference Attacks (MIAs) assume adversaries possess complete knowledge of a target's features, we formalize a highly realistic threat model where attackers observe only partial records. To exploit this, we introduce the Missing Features-Membership Inference Attack (MF-MIA), a practical two-stage black-box framework. MF-MIA first imputes with-held attributes using auxiliary data with overlapping features, and subsequently mounts a shadow-model-based MIA on the completed queries. In a cross-database case study (target model trained on the General Social Survey; auxiliary data from UCI Adult), MF-MIA achieves up to 59.3% membership accuracy even when a sensitive feature is entirely withheld. By benchmarking multiple completion strategies, including statistical priors, model-based imputation, TVAE, and masked autoencoders, we show that attack power scales with imputation quality, independent of target-model feature importance. Finally, we demonstrate that Large Language Models (LLMs) can effectively substitute for tabular auxiliary data in data-scarce environments, decisively proving that feature masking cannot stand alone as a robust privacy defense.
KW - AI privacy
KW - Machine Learning
KW - Membership Inference Attack
UR - https://www.scopus.com/pages/publications/105045577320
U2 - 10.1109/ICSTW72326.2026.00054
DO - 10.1109/ICSTW72326.2026.00054
M3 - Conference contribution
AN - SCOPUS:105045577320
T3 - Proceedings - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026
SP - 288
EP - 297
BT - Proceedings - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026
PB - Institute of Electrical and Electronics Engineers
Y2 - 18 May 2026 through 22 May 2026
ER -