A Fusion-Denoising Attack on InstaHide with Data Augmentation
Xinjian Luo, Xiaokui Xiao, Yuncheng Wu, Juncheng Liu, Beng Chin Ooi
Abstract
InstaHide is a state-of-the-art mechanism for protecting private training images, by mixing multiple private images and modifying them such that their visual features are indistinguishable to the naked eye. In recent work, however, Carlini et al. show that it is possible to reconstruct private images from the encrypted dataset generated by InstaHide. Nevertheless, we demonstrate that Carlini et al.’s attack can be easily defeated by incorporating data augmentation into InstaHide. This leads to a natural question: is InstaHide with data augmentation secure? In this paper, we provide a negative answer to this question, by devising an attack for recovering private images from the outputs of InstaHide even when data augmentation is present. The basic idea is to use a comparative network to identify encrypted images that are likely to correspond to the same private image, and then employ a fusion-denoising network for restoring the private image from the encrypted ones, taking into account the effects of data augmentation. Extensive experiments demonstrate the effectiveness of the proposed attack in comparison to Carlini et al.’s attack.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ecdb01c9-42dd-4784-9a0c-e0dd6adfc360Cited by top-tier papers2
- Feature Inference Attack on Shapley ValuesXinjian Luo, Yangfan Jiang, Xiaokui XiaoCCS 2022 · 20 citations
- LDP-Slicing: Local Differential Privacy for Images via Randomized Bit-Plane SlicingYuanming Cao, Chengqi Li, Wenbo HeCVPR 2026 · 2 citations
Builds on4
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
- Privacy Preserving Vertical Federated Learning for Tree-based ModelsYuncheng Wu, Shaofeng Cai, Xiaokui Xiao, Gang Chen et al.VLDB 2020 · 259 citations
- Feature Inference Attack on Model Predictions in Vertical Federated LearningXinjian Luo, Yuncheng Wu, Xiaokui Xiao, Beng Chin OoiICDE 2021 · 212 citations
- InstaHide: Instance-hiding Schemes for Private Distributed LearningYangsibo Huang, Zhao Song, Kai Li, Sanjeev AroraICML 2020 · 178 citations
Related papers
- Is Private Learning Possible with Instance Encoding?Nicholas Carlini, Samuel Deng, Sanjam Garg, Somesh Jha et al.S&P 2021 · 45 citations
- On InstaHide, Phase Retrieval, and Sparse Matrix FactorizationSitan Chen, Xiaoxiao Li, Zhao Song, Danyang ZhuoICLR 2021 · 1 citation
- Dropout Is NOT All You Need to Prevent Gradient LeakageDaniel Scheliga, Patrick Maeder, Marco SeelandAAAI 2023 · 22 citations
- Privacy-Preserving Collaborative Learning With Automatic Transformation SearchWei Gao, Shangwei Guo, Tianwei Zhang, Han Qiu et al.CVPR 2021
- Don't Trust the AI Ecosystem: Analyzing Privacy Leakage in Compromised Open-Source ComponentsJin-Seong Kim, Han-Ju Lee, Seok-Won Hong, Takeshi Takahashi et al.CCS 2026
