Batch Normalization Amplifies Memorization and Privacy Risks
Quick summary
arXiv:2605.24420v2 Announce Type: replace-cross Abstract: Batch Normalization (BN) is widely adopted to enable faster convergence and more stable training of deep neural networks. However, its impact on privacy and memorization has remained largely unexplored. In this work, we investigate the effect of BN layers on the memorization of atypical or outlier samples and its implications for privacy leakage. We conduct an extensive empirical study using three complementary approaches: (i) unintended memorization of out-of-distribution samples, (ii) per-sample influence, and (iii) susceptibility to
Key takeaways
- arXiv:2605.24420v2 Announce Type: replace-cross Abstract: Batch Normalization (BN) is widely adopted to enable faster convergence and more stable training of deep neural networks.
- However, its impact on privacy and memorization has remained largely unexplored.
- In this work, we investigate the effect of BN layers on the memorization of atypical or outlier samples and its implications for privacy leakage.
Why it matters
“Batch Normalization Amplifies Memorization and Privacy Risks” may affect what data AI products can use and where accountability sits. Product teams should watch compliance duties, rights holders should watch enforcement, and users should watch transparency and appeal mechanisms.

Member comments