The goal of membership inference attack is to predict whether given datapoints are part of a large language model's training data. One way to do this is to train a shadow model.