Label-Only Model Inversion Attacks via Knowledge Transfer
Ngoc-Bao Nguyen, Keshigeyan Chandrasegaran, Milad Abdollahzadeh, Ngai-Man Cheung
摘要
In a model inversion (MI) attack, an adversary abuses access to a machine learning (ML) model to infer and reconstruct private training data. Remarkable progress has been made in the white-box and black-box setups, where the adversary has access to the complete model or the model's soft output respectively. However, there is very limited study in the most challenging but practically important setup: Label-only MI attacks, where the adversary only has access to the model's predicted label (hard label) without confidence scores nor any other model information. In this work, we propose LOKT, a novel approach for label-only MI attacks. Our idea is based on transfer of knowledge from the opaque target model to surrogate models. Subsequently, using these surrogate models, our approach can harness advanced white-box attacks. We propose knowledge transfer based on generative modelling, and introduce a new model, Target model-assisted ACGAN (T-ACGAN), for effective knowledge transfer. Our method casts the challenging label-only MI into the more tractable white-box setup. We provide analysis to support that surrogate models based on our approach serve as effective proxies for the target model for MI. Our experiments show that our method significantly outperforms existing SOTA Label-only MI attack by more than 15% across all MI benchmarks. Furthermore, our method compares favorably in terms of query budget. Our study highlights rising privacy threats for ML models even when minimal information (i.e., hard labels) is exposed. Our study highlights rising privacy threats for ML models even when minimal information (i.e., hard labels) is exposed. Our code, demo, models and reconstructed data are available at our project page: https://ngoc-nguyen-0.github.io/lokt/
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Pseudo-Private Data Guided Model Inversion AttacksXiong Peng, Bo Han, Feng Liu, Tongliang Liu 等NeurIPS 2024 · 被引用 12 次
- Generative Model Inversion Through the Lens of the Manifold HypothesisXiong Peng, Bo Han, Fengfei Yu, Tongliang Liu 等NeurIPS 2025 · 被引用 3 次
- Do Vision-Language Models Leak What They Learn? Adaptive Token-Weighted Model Inversion AttacksNgoc-Bao Nguyen, Sy-Tuyen Ho, Koh Jun Hao, Ngai-Man CheungCVPR 2026 · 被引用 2 次
- Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature FilteringHongyao Yu, Yixiang Qiu, Hao Fang, Tianqu Zhuang 等KDD 2026 · 被引用 2 次
- Reducing information dependency does not cause training data privacy. Adversarially non-robust features do.Rasmus Torp, Shailen Smith, Adam BreuerICLR 2026 · 被引用 1 次
它引用的顶会 Paper22
- Supervised Contrastive LearningPrannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna 等NeurIPS 2020 · 被引用 7,049 次
- Neural Network Inversion in Adversarial Setting via Background Knowledge AlignmentZiqi Yang, Jiyi Zhang, Ee-Chien Chang, Zhenkai LiangCCS 2019 · 被引用 257 次
- Variational Model Inversion AttacksKuan-Chieh Wang, Yan Fu, Ke Li, Ashish Khisti 等NeurIPS 2021 · 被引用 142 次
- Knowledge-Enriched Distributional Model Inversion AttacksSi Chen, Mostafa Kahla, Ruoxi Jia, Guo-Jun QiICCV 2021 · 被引用 124 次
- Improving Robustness to Model Inversion Attacks via Mutual Information RegularizationTianhao Wang, Yuheng Zhang, Ruoxi JiaAAAI 2021 · 被引用 98 次
相关 Paper
- Reinforcement Learning-Based Black-Box Model Inversion AttacksGyojin Han, Jaehyun Choi, Haeil Lee, Junmo KimCVPR 2023
- Label-Only Model Inversion Attacks via Boundary RepulsionMostafa Kahla, Si Chen, Hoang Anh Just, Ruoxi JiaCVPR 2022 · 被引用 60 次
- Pseudo Label-Guided Model Inversion Attack via Conditional Generative Adversarial NetworkXiaojian Yuan, Kejiang Chen, Jie Zhang, Weiming Zhang 等AAAI 2023 · 被引用 57 次
- Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification ModelsShagufta Mehnaz, Sayanton V. Dibbo, Ehsanul Kabir, Ninghui Li 等USENIX Security 2022
- Data-Free Model ExtractionJean-Baptiste Truong, Pratyush Maini, Robert J. Walls, Nicolas PapernotCVPR 2021
