A attack on a pretrained model that tests if data is part of the training set. Model will behave differently if it already knows the answer.