PofoliaShared via Pofolia

ACM Transactions on Multimedia Computing Communications and Applications· 2026Q1

Model Inversion Attacks Through Target-Specific Conditional Diffusion Models

Ouxiang Li, Yanbin Hao, Zhicai Wang, Bin Zhu et al.

Short summary

A new method, Diff-MI, uses conditional diffusion models to reconstruct private training images from AI classifiers with 20% better fidelity (lower FID) than previous attacks.

AI-generated from the title and abstract; the full text is not read.

Abstract

Model inversion attacks (MIAs) aim to reconstruct private images from a target classifier's training set, thereby raising privacy concerns in AI applications. Previous GAN-based MIAs tend to suffer from inferior generative fidelity due to GANs’ inherent flaws and biased optimization within the latent space. To alleviate these issues, leveraging diffusion models’ remarkable synthesis capabilities, we propose Diffusion-based Model Inversion (Diff-MI) attacks. Specifically, we introduce a novel target-specific conditional diffusion model (CDM) to purposely approximate the target classifier's private data distribution and achieve a superior accuracy-fidelity balance. Our method involves a two-step learning paradigm. Step-1 incorporates the target classifier into the entire CDM learning under a pretrain-then-finetune fashion, by creating pseudo-labels as model conditions in pretraining and optimizing specified layers with image predictions in fine-tuning. Step-2 presents an iterative image reconstruction method, further enhancing the attack performance through a combination of diffusion priors and target knowledge. Additionally, we propose an improved max-margin loss that replaces the hard max with top-k maxes, fully leveraging feature information and soft labels from the target classifier. Extensive experiments demonstrate that Diff-MI significantly improves generative fidelity with an average decrease of 20% in FID while maintaining competitive attack accuracy compared to state-of-the-art methods across various datasets and models. Our code is available at: https://github.com/Ouxiang-Li/Diff-MI .

The authors' abstract, as published at the source. ACM Transactions on Multimedia Computing Communications and Applications, 2026 · DOI ↗

TakeawaysIn the app
Key pointsIn the app
Ask the paperIn the app

The rest is in the Pofolia app

Takeaways, key points and questions to the paper; new summaries every day for your field. Free.

Sign in on the web to open

Field: Statistical and Nonlinear Physics

Statistical and Nonlinear PhysicsPhysics and Astronomy