Weight spectral metrics provide a computationally cheap alternative to shadow model attacks for assessing privacy risk, enabling large-scale privacy audits of machine learning models.
This paper shows that spectral properties of neural network weights—like stable rank and log alpha-norm—can predict privacy leakage risk without expensive shadow model training. By analyzing weight spectra, researchers found these metrics correlate with membership inference attack success better than traditional overfitting measures, offering a faster way to audit model privacy.