paper-with-me

홈 › Papers

Model Inversion Attack via Dynamic Memory Learning

2023-08-24 · Gege Qi, Yuefeng Chen, Xiaofeng Mao, Binyuan Hui, Xiaodan Li, Rong Zhang, Hui Xue

Model Inversion (MI) attacks aim to recover the private training data from the target model, which has raised security concerns about the deployment of DNNs in practice. Recent advances in generative adversarial models have rendered them particularly effective in MI attacks, primarily due to their ability to generate high-fidelity and perceptually realistic images that closely resemble the target data. In this work, we propose a novel Dynamic Memory Model Inversion Attack (DMMIA) to leverage historically learned knowledge, which interacts with samples (during the training) to induce diverse generations. DMMIA constructs two types of prototypes to inject the information about historically learned knowledge: Intra-class Multicentric Representation (IMR) representing target-related concepts by multiple learnable prototypes, and Inter-class Discriminative Representation (IDR) characterizing the memorized samples as learned prototypes to capture more privacy-related information. As a result, our DMMIA has a more informative representation, which brings more diverse and discriminative generated results. Experiments on multiple benchmarks show that DMMIA performs better than state-of-the-art MI attack methods.

📄 PDF Abstract BibTeX arXiv:2309.00013

Code (0)

등록된 구현이 없습니다.

Tasks

model

Similar Papers 제목 키워드 기반

Chunked Lists versus Extensible Arrays for Text Inversion

2023-08-29 · David Hawking, Bodo Billerbeck

In our 2017 work on in-memory list-based text inversion [Hawking and Billerbeck. Efficient In-Memory, List-Based Text Inversion. ADCS 2017] we compared memory use and indexing speed of a considerable number of variants o…

Chunking

FuSeFL: Fully Secure and Scalable Federated Learning

2025-07-18 · Sahar Ghoflsaz Ghinani, Elaheh Sadredini arxiv

Federated Learning (FL) enables collaborative model training without centralizing client data, making it attractive for privacy-sensitive domains. While existing approaches employ cryptographic techniques such as homomor…

Federated Learning

Reinforcement Learning-Based Black-Box Model Inversion Attacks

2023-04-10 · CVPR 2023 1 · Gyojin Han, Jaehyun Choi, Haeil Lee, Junmo Kim

Model inversion attacks are a type of privacy attack that reconstructs private data used to train a machine learning model, solely by accessing the model. Recently, white-box model inversion attacks leveraging Generative…

modelPrivacy Preservingreinforcement-learningReinforcement Learning

Mitigating Privacy Risks in LLM Embeddings from Embedding Inversion

2024-11-06 · Tiantian Liu, Hongwei Yao, Tong Wu, Zhan Qin 외

Embeddings have become a cornerstone in the functionality of large language models (LLMs) due to their ability to transform text data into rich, dense numerical representations that capture semantic and syntactic propert…

ALGEN: Few-shot Inversion Attacks on Textual Embeddings using Alignment and Generation

2025-02-16 · Yiyi Chen, Qiongkai Xu, Johannes Bjerva

With the growing popularity of Large Language Models (LLMs) and vector databases, private textual data is increasingly processed and stored as numerical embeddings. However, recent studies have proven that such embedding…