PofoliaPofolia ile paylaşıldı

ACM Transactions on Multimedia Computing Communications and Applications· 2026Q1

Yapay Zeka Görüntü Sınıflandırıcılarına Yönelik Gizlilik Saldırılarını Yayılma Modelleriyle Güçlendirme

Model Inversion Attacks Through Target-Specific Conditional Diffusion Models

Ouxiang Li, Yanbin Hao, Zhicai Wang, Bin Zhu ve diğerleri

Kısa özet

Koşullu yayılma modellerini kullanan yeni bir yöntem olan Diff-MI, yapay zeka sınıflandırıcılarından özel eğitim görüntülerini %20 daha iyi sadakatle (daha düşük FID) yeniden oluşturuyor.

Yapay zekâ ile başlık ve abstract'tan üretildi; tam metin okunmaz.

Özet (abstract)

Model inversion attacks (MIAs) aim to reconstruct private images from a target classifier's training set, thereby raising privacy concerns in AI applications. Previous GAN-based MIAs tend to suffer from inferior generative fidelity due to GANs’ inherent flaws and biased optimization within the latent space. To alleviate these issues, leveraging diffusion models’ remarkable synthesis capabilities, we propose Diffusion-based Model Inversion (Diff-MI) attacks. Specifically, we introduce a novel target-specific conditional diffusion model (CDM) to purposely approximate the target classifier's private data distribution and achieve a superior accuracy-fidelity balance. Our method involves a two-step learning paradigm. Step-1 incorporates the target classifier into the entire CDM learning under a pretrain-then-finetune fashion, by creating pseudo-labels as model conditions in pretraining and optimizing specified layers with image predictions in fine-tuning. Step-2 presents an iterative image reconstruction method, further enhancing the attack performance through a combination of diffusion priors and target knowledge. Additionally, we propose an improved max-margin loss that replaces the hard max with top-k maxes, fully leveraging feature information and soft labels from the target classifier. Extensive experiments demonstrate that Diff-MI significantly improves generative fidelity with an average decrease of 20% in FID while maintaining competitive attack accuracy compared to state-of-the-art methods across various datasets and models. Our code is available at: https://github.com/Ouxiang-Li/Diff-MI .

Yazarların özeti; kaynağından alınmıştır. ACM Transactions on Multimedia Computing Communications and Applications, 2026 · DOI ↗

ÇıkarımlarUygulamada
Ana noktalarUygulamada
Makaleye SorUygulamada

Devamı Pofolia uygulamasında

Çıkarımlar, ana noktalar ve makaleye soru sorma; ilgi alanına göre her gün yeni özetler. Ücretsiz.

Web'de giriş yaparak aç

Alan: İstatistiksel ve Doğrusal Olmayan Fizik

Statistical and Nonlinear PhysicsPhysics and Astronomy