Understanding what generative models retain from training data remains challenging, with implications for copyright and privacy.<br>Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We study this regime for Rectified Flows, which are increasingly used in deployed generative systems.<br>We analyse the interpolation path $X_\\lambda = (1-\\lambda)X_0 + \\lambda X_1$ that defines the Rectified Flow training.<br>We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over $\\lambda$, wich accumulates during training, while the validation metrics remain stable.<br>The signal has a maximum whose location we derive in closed form under Gaussian assumptions.<br>We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied.<br>As a proof of concept, we exploit this specific $\\lambda$-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.</p>\n","updatedAt":"2026-06-09T13:29:45.242Z","author":{"_id":"68905f385bce85370d0a1050","avatarUrl":"/avatars/90fdad22fa32f56c62f11f13ae62fe4a.svg","fullname":"Thomas Sesmat","name":"ThomSes","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.9287779331207275},"editors":["ThomSes"],"editorAvatarUrls":["/avatars/90fdad22fa32f56c62f11f13ae62fe4a.svg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2606.07271","authors":[{"_id":"6a27cf826dde1c5ef75bd27e","user":{"_id":"68905f385bce85370d0a1050","avatarUrl":"/avatars/90fdad22fa32f56c62f11f13ae62fe4a.svg","isPro":false,"fullname":"Thomas Sesmat","user":"ThomSes","type":"user","name":"ThomSes"},"name":"Thomas Sesmat","status":"claimed_verified","statusLastChangedAt":"2026-06-09T12:40:55.701Z","hidden":false},{"_id":"6a27cf826dde1c5ef75bd27f","name":"Gabriel Meseguer-Brocal","hidden":false},{"_id":"6a27cf826dde1c5ef75bd280","name":"Geoffroy Peeters","hidden":false}],"publishedAt":"2026-06-05T13:46:37.000Z","submittedOnDailyAt":"2026-06-09T00:00:00.000Z","title":"Where Rectified Flows Leak: Characterising Membership Signals Along the Interpolation Path","submittedOnDailyBy":{"_id":"68905f385bce85370d0a1050","avatarUrl":"/avatars/90fdad22fa32f56c62f11f13ae62fe4a.svg","isPro":false,"fullname":"Thomas Sesmat","user":"ThomSes","type":"user","name":"ThomSes"},"summary":"Understanding what generative models retain from training data remains challenging, with implications for copyright and privacy. Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We study this regime for Rectified Flows, which are increasingly used in deployed generative systems. We analyse the interpolation path X_λ= (1-λ)X_0 + λX_1 that defines the Rectified Flow training. We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over λ, wich accumulates during training, while the validation metrics remain stable. The signal has a maximum whose location we derive in closed form under Gaussian assumptions. We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied. As a proof of concept, we exploit this specific λ-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.","upvotes":1,"discussionId":"6a27cf826dde1c5ef75bd281","githubRepo":"https://github.com/sourisimos/rectified_flow_membership","githubRepoAddedBy":"user","ai_summary":"Rectified Flows retain subtle training data traces that accumulate during training and can be exploited for membership inference attacks.","ai_keywords":["Rectified Flows","membership inference attack","training data retention","interpolation path","reconstruction gap","bell-shaped curve","Gaussian assumptions"],"ai_summary_model":"Qwen/Qwen2.5-Coder-32B-Instruct","githubStars":0,"organization":{"_id":"5fe0a3b39126717e4c356efa","name":"Telecom-Paris","fullname":"Telecom Paris","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/1608557374722-5fce3ed4e80c09ad2760251b.jpeg"}},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"68905f385bce85370d0a1050","avatarUrl":"/avatars/90fdad22fa32f56c62f11f13ae62fe4a.svg","isPro":false,"fullname":"Thomas Sesmat","user":"ThomSes","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"organization":{"_id":"5fe0a3b39126717e4c356efa","name":"Telecom-Paris","fullname":"Telecom Paris","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/1608557374722-5fce3ed4e80c09ad2760251b.jpeg"},"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2606/2606.07271.md"}">
Where Rectified Flows Leak: Characterising Membership Signals Along the Interpolation Path
Abstract
Rectified Flows retain subtle training data traces that accumulate during training and can be exploited for membership inference attacks.
Understanding what generative models retain from training data remains challenging, with implications for copyright and privacy. Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We study this regime for Rectified Flows, which are increasingly used in deployed generative systems. We analyse the interpolation path X_λ= (1-λ)X_0 + λX_1 that defines the Rectified Flow training. We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over λ, wich accumulates during training, while the validation metrics remain stable. The signal has a maximum whose location we derive in closed form under Gaussian assumptions. We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied. As a proof of concept, we exploit this specific λ-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.
Community
Understanding what generative models retain from training data remains challenging, with implications for copyright and privacy.
Beyond verbatim reproduction, models can encode subtler traces of their training data that never surface in their outputs yet remain exploitable. We study this regime for Rectified Flows, which are increasingly used in deployed generative systems.
We analyse the interpolation path $X_\lambda = (1-\lambda)X_0 + \lambda X_1$ that defines the Rectified Flow training.
We show that a gap exists between the reconstruction of train and test data that follows a bell-shaped curve over $\lambda$, wich accumulates during training, while the validation metrics remain stable.
The signal has a maximum whose location we derive in closed form under Gaussian assumptions.
We validate these predictions on both audio and images and show that the bell-shaped structure is universal, while the peak prediction holds when our assumptions are satisfied.
As a proof of concept, we exploit this specific $\lambda$-resolved structure to perform a Membership Inference Attack, distinguishing members of the training set from non-members.
Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images
Cite arxiv.org/abs/2606.07271 in a model README.md to link it from this page.
Cite arxiv.org/abs/2606.07271 in a dataset README.md to link it from this page.
Cite arxiv.org/abs/2606.07271 in a Space README.md to link it from this page.
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.