AIセキュリティポータル K Program
Random Erasing vs. Model Inversion: A Promising Defense or a False Hope?
Share
Abstract
Model Inversion (MI) attacks pose a significant privacy threat by reconstructing private training data from machine learning models. While existing defenses primarily concentrate on model-centric approaches, the impact of data on MI robustness remains largely unexplored. In this work, we explore Random Erasing (RE), a technique traditionally used for improving model generalization under occlusion, and uncover its surprising effectiveness as a defense against MI attacks. Specifically, our novel feature space analysis shows that models trained with RE-images introduce a significant discrepancy between the features of MI-reconstructed images and those of the private data. At the same time, features of private images remain distinct from other classes and well-separated from different classification regions. These effects collectively degrade MI reconstruction quality and attack accuracy while maintaining reasonable natural accuracy. Furthermore, we explore two critical properties of RE including Partial Erasure and Random Location. Partial Erasure prevents the model from observing entire objects during training. We find this has a significant impact on MI, which aims to reconstruct the entire objects. Random Location of erasure plays a crucial role in achieving a strong privacy-utility trade-off. Our findings highlight RE as a simple yet effective defense mechanism that can be easily integrated with existing privacy-preserving techniques. Extensive experiments across 37 setups demonstrate that our method achieves state-of-the-art (SOTA) performance in the privacy-utility trade-off. The results consistently demonstrate the superiority of our defense over existing methods across different MI attacks, network architectures, and attack configurations. For the first time, we achieve a significant degradation in attack accuracy without a decrease in utility for some configurations.
Mirror: Model inversion for deep learning network with high fidelity
S. An, G. Tao, Q. Xu, Y. Liu, G. Shen, Y. Yao, J. Xu, X. Zhang
Published: 2022
Medical diagnosis using deep learning techniques: a research survey
Mir Mohammad Azad, Apoorva Ganapathy, Siddhartha Vadlamudi, Harish Paruchuri
Published: 2021
Vggface2: A dataset for recognising faces across pose and age
Qiong Cao, Li Shen, Weidi Xie, Omkar M Parkhi, Andrew Zisserman
Published: 2018
Knowledge-enriched distributional model inversion attacks
Si Chen, Mostafa Kahla, Ruoxi Jia, Guo-Jun Qi
Published: 2021
Know you at one glance: A compact vector representation for low-shot learning
Yu Cheng, Jian Zhao, Zhecan Wang, Yan Xu, Karlekar Jayashree, Shengmei Shen, Jiashi Feng
Published: 2017
Stargan v2: Diverse image synthesis for multiple domains
Yunjey Choi, Youngjung Uh, Jaejun Yoo, Jung-Woo Ha
Published: 2020
Novel datasets for fine-grained image categorization
E Dataset
Published: 2011
New types of deep neural network learning for speech recognition and related applications: An overview
Li Deng, Geoffrey Hinton, Brian Kingsbury
Published: 2013
Differential privacy
Cynthia Dwork
Published: 2006
Differential privacy: A survey of results
C. Dwork
Published: 2008
A gan-based defense framework against model inversion attacks
Xueluan Gong, Ziyao Wang, Shuaike Li, Yanjiao Chen, Qian Wang
Published: 2023
A survey on deep learning based face recognition
Guodong Guo, Na Zhang
Published: 2019
Reinforcement Learning-Based Black-Box Model Inversion Attacks
Gyojin Han, Jaehyun Choi, Haeil Lee, Junmo Kim
Published: 2023.4.10
Vision-face recognition attendance monitoring system for surveillance using deep learning technology and computer vision
J Harikrishnan, Arya Sudarsan, Aravind Sadashiv, Remya AS Ajai
Published: 2019
Application of deep learning for weapons detection in surveillance videos
Tufail Sajjad Shah Hashmi, Nazeef Ul Haq, Muhammad Moazam Fraz, Muhammad Shahzad
Published: 2021
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
Densely connected convolutional networks
G. Huang, Z. Liu, L. Van Der Maaten, K. Q. Weinberger
Published: 2017
Label-only model inversion attacks via boundary repulsion
Mostafa Kahla, Si Chen, Hoang Anh Just, Ruoxi Jia
Published: 2022
A style-based generator architecture for generative adversarial networks
T. Karras, S. Laine, T. Aila
Published: 2019
On the vulnerability of skip connections to model inversion attacks
Jun Hao Koh, Sy-Tuyen Ho, Ngoc-Bao Nguyen, Ngai-man Cheung
Published: 2024
Deep learning
Yann LeCun, Yoshua Bengio, Geoffrey Hinton
Published: 2015
Deep Learning Face Attributes in the Wild
Ziwei Liu, Ping Luo, Xiaogang Wang, Xiaoou Tang
Published: 2015
An overview of deep learning in medical imaging focusing on mri
Alexander Selvikvåg Lundervold, Arvid Lundervold
Published: 2019
Deep face recognition: A survey
Iacopo Masi, Yue Wu, Tal Hassner, Prem Natarajan
Published: 2018
Speech recognition using deep neural networks: A systematic review
Ali Bou Nassif, Ismail Shahin, Imtinan Attili, Mohammad Azzeh, Khaled Shaalan
Published: 2019
A data-driven approach to cleaning large face datasets
Hong-Wei Ng, Stefan Winkler
Published: 2014
Re-thinking model inversion attacks against deep neural networks
N.-B. Nguyen, K. Chandrasegaran, M. Abdollahzadeh, N.-M. Cheung
Published: 2023
A survey of the usages of deep learning for natural language processing
Daniel W Otter, Julian R Medina, Jugal K Kalita
Published: 2020
Deep learning vs. traditional computer vision
Niall O’Mahony, Sean Campbell, Anderson Carvalho, Suman Harapanahalli, Gustavo Velasco Hernandez, Lenka Krpalkova, Daniel Riordan, Joseph Walsh
Published: 2020
Bilateral dependency optimization: Defending against model-inversion attacks
Xiong Peng, Feng Liu, Jingfeng Zhang, Long Lan, Junjie Ye, Tongliang Liu, Bo Han
Published: 2022
Pseudo-private data guided model inversion attacks
Xiong Peng, Bo Han, Feng Liu, Tongliang Liu, Mingyuan Zhou
Published: 2024
Model inversion attack via dynamic memory learning
Gege Qi, YueFeng Chen, Xiaofeng Mao, Binyuan Hui, Xiaodan Li, Rong Zhang, Hui Xue
Published: 2023
A closer look at gan priors: Exploiting intermediate features for enhanced model inversion attacks
Yixiang Qiu, Hao Fang, Hongyao Yu, Bin Chen, MeiKang Qiu, Shu-Tao Xia
Published: 2024
Facenet: A unified embedding for face recognition and clustering
F. Schroff, D. Kalenichenko, J. Philbin
Published: 2015
Deep learning in medical image analysis
Dinggang Shen, Guorong Wu, Heung-Il Suk
Published: 2017
Very deep convolutional networks for large-scale image recognition
K. Simonyan, A. Zisserman
Published: 2015
Plug & play attacks: Towards robust and flexible model inversion attacks
Lukas Struppek, Dominik Hintersdorf, Antonio De Almeida Correira, Antonia Adler, Kristian Kersting
Published: 2022
Be careful what you smooth for: Label smoothing can be a privacy shield but also a catalyst for model inversion attacks
Lukas Struppek, Dominik Hintersdorf, Kristian Kersting
Published: 2024
An image inpainting technique based on the fast marching method
Alexandru Telea
Published: 2004
Maxvit: Multi-axis vision transformer
Zhengzhong Tu, Hossein Talebi, Han Zhang, Feng Yang, Peyman Milanfar, Alan Bovik, Yinxiao Li
Published: 2022
Deep learning for computer vision: A brief review
Athanasios Voulodimos, Nikolaos Doulamis, Anastasios Doulamis, Eftychios Protopapadakis
Published: 2018
Deep face recognition: A survey
Mei Wang, Weihong Deng
Published: 2021
Improving robustness to model inversion attacks via mutual information regularization
T. Wang, Y. Zhang, R. Jia
Published: 2020
Pseudo label-guided model inversion attack via conditional generative adversarial network
Xiaojian Yuan, Kejiang Chen, Jie Zhang, Weiming Zhang, Nenghai Yu, Yang Zhang
Published: 2023
The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks
Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, Dawn Song
Published: 2019.11.17
Random erasing data augmentation
Zhun Zhong, Liang Zheng, Guoliang Kang, Shaozi Li, Yi Yang
Published: 2020
Deep-learning-enhanced multitarget detection for end–edge–cloud surveillance in smart iot
Xiaokang Zhou, Xuesong Xu, Wei Liang, Zhi Zeng, Zheng Yan
Published: 2021
Share