Do Vision-Language Models Leak What They Learn? Adaptive Token-Weighted Model Inversion Attacks
Ngoc-Bao Nguyen, Sy-Tuyen Ho, Koh Jun Hao, Ngai-Man Cheung
Abstract
Model inversion (MI) attacks pose significant privacy risks by reconstructing private training data from trained neural networks. While prior studies have primarily examined unimodal deep networks, the vulnerability of vision-language models (VLMs) remains largely unexplored. **In this work, we present the first systematic study of MI attacks on VLMs to understand their susceptibility to leaking private visual training data.**Our work makes two main contributions.First, tailored to the token-generative nature of VLMs,we introduce a suite of token-based and sequence-based model inversion strategies, providing a comprehensive analysis of VLMs' vulnerability under different attack formulations.Second, based on the observation that tokens vary in their visual grounding, and hencetheir gradients differ in informativeness for image reconstruction, we propose Sequence-based Model Inversion with Adaptive Token Weighting (SMI-AW) as a novel MI for VLMs. SMI-AW dynamically reweights each token's loss gradient according to its visual grounding, enabling the optimization to focus on visually informative tokens and more effectively guide the reconstruction of private images.Through extensive experiments and human evaluations on a range of state-of-the-art VLMs across multiple datasets, we show that VLMs are susceptible to training data leakage. Human evaluation of the reconstructed images yields an attack accuracy of 61.21%, underscoring the severity of these privacy risks.Notably, we demonstrate that publicly released VLMs are vulnerable to such attacks. Our study highlights the urgent need for privacy safeguards as VLMs become increasingly deployed in sensitive domains such as healthcare and finance. Code and additional experiments are provided in Supp.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3661b25b-412d-4235-997d-2fe5509b04e9Builds on19
- Neural Network Inversion in Adversarial Setting via Background Knowledge AlignmentZiqi Yang, Jiyi Zhang, Ee-Chien Chang, Zhenkai LiangCCS 2019 · 257 citations
- Variational Model Inversion AttacksKuan-Chieh Wang, Yan Fu, Ke Li, Ashish Khisti et al.NeurIPS 2021 · 142 citations
- Knowledge-Enriched Distributional Model Inversion AttacksSi Chen, Mostafa Kahla, Ruoxi Jia, Guo-Jun QiICCV 2021 · 124 citations
- Improving Robustness to Model Inversion Attacks via Mutual Information RegularizationTianhao Wang, Yuheng Zhang, Ruoxi JiaAAAI 2021 · 98 citations
- Plug & Play Attacks: Towards Robust and Flexible Model Inversion AttacksLukas Struppek, Dominik Hintersdorf, Antonio De Almeida Correia, Antonia Adler et al.ICML 2022 · 88 citations
Related papers
- VLMs can Aggregate Scattered Training PatchesZhanhui Zhou, Lingjie Chen, Chao Yang, Chaochao LuNeurIPS 2025
- Membership Inference Attacks Against Vision-Language ModelsYuke Hu, Zheng Li, Zhihao Liu, Yang Zhang et al.USENIX Security 2025
- Re-Thinking Model Inversion Attacks Against Deep Neural NetworksNgoc-Bao Nguyen, Keshigeyan Chandrasegaran, Milad Abdollahzadeh, Ngai-Man CheungCVPR 2023
- Membership Inference Attacks against Large Vision-Language ModelsZhan Li, Yongtao Wu, Yihang Chen, Francesco Tonin et al.NeurIPS 2024 · 43 citations
- Geminio: Language-Guided Gradient Inversion Attacks in Federated LearningJunjie Shan, Ziqi Zhao, Jialin Lu, Rui Zhang et al.ICCV 2025 · 2 citations
