arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

自适应模型反演攻击泛化隐私-鲁棒性权衡

Adaptive Model Inversion Attacks Generalize a Privacy-Robustness Tradeoff

Shailen Smith, Rasmus Torp, Adam Breuer

arXiv 2610.07677首次发表:更新:

发表机构

Dartmouth College(达特茅斯学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文通过自适应攻击调整揭示标准模型反演攻击评估低估隐私泄露,并发现重建泄露与对抗鲁棒性紧密相关,提出鲁棒性可作为重建脆弱性的广泛代理。

AI 中文摘要

在本文中,我们表明对高分辨率模型反演攻击(MIAs)的标准评估显著低估了训练数据隐私泄露。最先进的隐私防御、标准训练技术(如MixUp和对抗训练)以及无防御模型,在FaceScrub数据集上,通过简单的自适应攻击变化,训练图像泄露率高出1.16至6.59倍,其中报告最强隐私的防御增幅最大。我们进一步表明,测量到的泄露取决于用于评估重建图像的外部分类器的特征基础:对于相同的重建图像,对抗训练的Inception评估器识别目标身份的比例与标准Inception评估器不同。我们的结果表明,标准MIA评估可能将优化和测量失败误认为隐私问题。这些被低估的泄露率也掩盖了隐私与对抗鲁棒性之间更广泛的关系。一旦我们调整攻击并改变评估器,重建泄露在最近的防御和标准训练机制中紧密跟踪对抗鲁棒性,这表明鲁棒性提供了与攻击无关的重建脆弱性代理,其适用范围比先前理论化的要广泛得多。这提出了一个开放性问题:实际防御能否在不付出相应对抗鲁棒性代价的情况下减少训练数据重建?

英文摘要

In this paper, we show that standard evaluations of high-resolution Model Inversion Attacks (MIAs) significantly underestimate training-data privacy leakage. State-of-the-art privacy defenses, standard training techniques such as MixUp and Adversarial Training, and undefended models all leak training images at rates 1.16 to 6.59 times higher on FaceScrub under simple adaptive changes to the attack, with the largest increases among defenses reporting the strongest privacy. We further show that measured leakage depends on the feature basis of the external classifier used to evaluate reconstructions: for the same reconstructed images, an adversarially trained Inception evaluator identifies the targeted identity at different rates than the standard Inception evaluator. Our results suggest that standard MIA evaluation can mistake optimization and measurement failures for privacy. These underestimated leakage rates also concealed a broader relationship between privacy and adversarial robustness. Once we adapt the attack and vary the evaluator, reconstruction leakage closely tracks adversarial robustness across recent defenses and standard training regimes, suggesting that robustness provides an attack-agnostic proxy for reconstruction vulnerability that applies far more broadly than previously theorized. This raises an open question: can a practical defense reduce training-data reconstruction without paying a corresponding cost in adversarial robustness?

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑