Where Rectified Flows Leak: Characterising Membership Signals Along the Interpolation Path
Abstract
Lay Summary
Generative AI systems that create music or images are trained on large datasets, raising concerns about what these models retain from their training data. Even when a model never reproduces a training sample exactly, it may still treat it differently from data it has never seen: reconstructing it more accurately, for instance. Can we detect and measure this effect? We studied this question for Rectified Flows, a technique behind popular systems like FLUX and Stable Audio. During training, each data sample is blended with random noise at varying levels. We found that the gap between how well the model reconstructs training data versus new data follows a predictable bell-shaped curve across these blending levels, and we derived a formula for where this gap is largest. Crucially, this signal builds up silently: standard training diagnostics show nothing unusual. We validated these predictions on both music and image datasets, and showed that a simple classifier exploiting this structure can reliably tell whether a given sample was used for training.