A Fusion-Denoising Attack on InstaHide with Data Augmentation
Xinjian Luo, Xiaokui Xiao, Yuncheng Wu, Juncheng Liu, Beng Chin Ooi
摘要
InstaHide is a state-of-the-art mechanism for protecting private training images, by mixing multiple private images and modifying them such that their visual features are indistinguishable to the naked eye. In recent work, however, Carlini et al. show that it is possible to reconstruct private images from the encrypted dataset generated by InstaHide. Nevertheless, we demonstrate that Carlini et al.’s attack can be easily defeated by incorporating data augmentation into InstaHide. This leads to a natural question: is InstaHide with data augmentation secure? In this paper, we provide a negative answer to this question, by devising an attack for recovering private images from the outputs of InstaHide even when data augmentation is present. The basic idea is to use a comparative network to identify encrypted images that are likely to correspond to the same private image, and then employ a fusion-denoising network for restoring the private image from the encrypted ones, taking into account the effects of data augmentation. Extensive experiments demonstrate the effectiveness of the proposed attack in comparison to Carlini et al.’s attack.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Feature Inference Attack on Shapley ValuesXinjian Luo, Yangfan Jiang, Xiaokui XiaoCCS 2022 · 被引用 20 次
- LDP-Slicing: Local Differential Privacy for Images via Randomized Bit-Plane SlicingYuanming Cao, Chengqi Li, Wenbo HeCVPR 2026 · 被引用 2 次
它引用的顶会 Paper4
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 被引用 1,581 次
- Privacy Preserving Vertical Federated Learning for Tree-based ModelsYuncheng Wu, Shaofeng Cai, Xiaokui Xiao, Gang Chen 等VLDB 2020 · 被引用 259 次
- Feature Inference Attack on Model Predictions in Vertical Federated LearningXinjian Luo, Yuncheng Wu, Xiaokui Xiao, Beng Chin OoiICDE 2021 · 被引用 212 次
- InstaHide: Instance-hiding Schemes for Private Distributed LearningYangsibo Huang, Zhao Song, Kai Li, Sanjeev AroraICML 2020 · 被引用 178 次
相关 Paper
- Is Private Learning Possible with Instance Encoding?Nicholas Carlini, Samuel Deng, Sanjam Garg, Somesh Jha 等S&P 2021 · 被引用 45 次
- On InstaHide, Phase Retrieval, and Sparse Matrix FactorizationSitan Chen, Xiaoxiao Li, Zhao Song, Danyang ZhuoICLR 2021 · 被引用 1 次
- Dropout Is NOT All You Need to Prevent Gradient LeakageDaniel Scheliga, Patrick Maeder, Marco SeelandAAAI 2023 · 被引用 22 次
- Privacy-Preserving Collaborative Learning With Automatic Transformation SearchWei Gao, Shangwei Guo, Tianwei Zhang, Han Qiu 等CVPR 2021
- Don't Trust the AI Ecosystem: Analyzing Privacy Leakage in Compromised Open-Source ComponentsJin-Seong Kim, Han-Ju Lee, Seok-Won Hong, Takeshi Takahashi 等CCS 2026
