arXiv:cs.LG· Shailen Smith, Rasmus Torp, Adam Breuer·· 4 小时前AI 评分46
自适应模型逆向攻击揭示隐私与鲁棒性的权衡关系
Adaptive Model Inversion Attacks Generalize a Privacy-Robustness Tradeoff
AI 导读
研究表明,标准的高分辨率模型逆向攻击(MIA)评估显著低估了训练数据隐私泄露,在 FaceScrub 上经简单自适应攻击调整后,MixUp、对抗训练等防御模型及无防御模型的泄露率高出 1.16 至 6.59 倍,且防御越强增幅越大。泄露率还取决于评估重建图像所用外部分类器的特征基。一旦调整攻击并更换评估器,重建泄露便与对抗鲁棒性高度吻合,提示鲁棒性可作为攻击无关的重建脆弱性代理指标。
正文
Abstract:In this paper, we show that standard evaluations of high-resolution Model Inversion Attacks (MIAs) significantly underestimate training-data privacy leakage. State-of-the-art privacy defenses, standard training techniques such as MixUp and Adversarial Training, and undefended models all leak training images at rates 1.16 to 6.59 times higher on FaceScrub under simple adaptive changes to the attack, with the largest increases among defenses reporting the strongest privacy. We further show that measured leakage depends on the feature basis of the external classifier used to evaluate reconstructions: for the same reconstructed images, an adversarially trained Inception evaluator identifies the targeted identity at different rates than the standard Inception evaluator. Our results suggest that standard MIA evaluation can mistake optimization and measurement failures for privacy.
These underestimated leakage rates also concealed a broader relationship between privacy and adversarial robustness. Once we adapt the attack and vary the evaluator, reconstruction leakage closely tracks adversarial robustness across recent defenses and standard training regimes, suggesting that robustness provides an attack-agnostic proxy for reconstruction vulnerability that applies far more broadly than previously theorized. This raises an open question: can a practical defense reduce training-data reconstruction without paying a corresponding cost in adversarial robustness?
| Subjects: | Machine Learning (cs.LG); Cryptography and Security (cs.CR) |
| Cite as: | arXiv:2610.07677 [cs.LG] |
| (or arXiv:2610.07677v1 [cs.LG] for this version) | |
| https://doi.org/10.48550/arXiv.2610.07677 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Adam Breuer [view email]
[v1]
Tue, 6 Oct 2026 03:11:19 UTC (2,291 KB)
来源:arXiv:cs.LG · arxiv.org