Plug & Play Attacks: Towards Robust and Flexible Model Inversion Attacks

被引:0
|
作者
Struppek, Lukas [1 ]
Hintersdorf, Dominik [1 ]
Correia, Antonio De Almeida [1 ]
Adler, Antonia [2 ]
Kersting, Kristian [1 ,3 ,4 ]
机构
[1] Tech Univ Darmstadt, Dept Comp Sci, Darmstadt, Germany
[2] Univ Bundeswehr Munchen, Munich, Germany
[3] Tech Univ Darmstadt, Ctr Cognit Sci, Darmstadt, Germany
[4] Hessian Ctr AI Hessian AI, Darmstadt, Germany
关键词
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Model inversion attacks (MIAs) aim to create synthetic images that reflect the class-wise characteristics from a target classifier's private training data by exploiting the model's learned knowledge. Previous research has developed generative MIAs that use generative adversarial networks (GANs) as image priors tailored to a specific target model. This makes the attacks time- and resource-consuming, inflexible, and susceptible to distributional shifts between datasets. To overcome these drawbacks, we present Plug & Play Attacks, which relax the dependency between the target model and image prior, and enable the use of a single GAN to attack a wide range of targets, requiring only minor adjustments to the attack. Moreover, we show that powerful MIAs are possible even with publicly available pre-trained GANs and under strong distributional shifts, for which previous approaches fail to produce meaningful results. Our extensive evaluation confirms the improved robustness and flexibility of Plug & Play Attacks and their ability to create high-quality images revealing sensitive class characteristics.
引用
收藏
页数:24
相关论文
共 50 条
  • [31] Label-Only Model Inversion Attacks via Knowledge Transfer
    Ngoc-Bao Nguyen
    Chandrasegaran, Keshigeyan
    Abdollahzadeh, Milad
    Cheung, Ngai-Man
    ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 36 (NEURIPS 2023), 2023,
  • [32] A GAN-Based Defense Framework Against Model Inversion Attacks
    Gong, Xueluan
    Wang, Ziyao
    Li, Shuaike
    Chen, Yanjiao
    Wang, Qian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2023, 18 : 4475 - 4487
  • [33] Practical Black Box Model Inversion Attacks Against Neural Nets
    Bekman, Thomas
    Abolfathi, Masoumeh
    Jafarian, Haadi
    Biswas, Ashis
    Banaei-Kashani, Farnoush
    Das, Kuntal
    MACHINE LEARNING AND PRINCIPLES AND PRACTICE OF KNOWLEDGE DISCOVERY IN DATABASES, PT II, 2021, 1525 : 39 - 54
  • [34] Bilateral Dependency Optimization: Defending Against Model-inversion Attacks
    Peng, Xiong
    Liu, Feng
    Zhang, Jingfeng
    Lan, Long
    Ye, Junjie
    Liu, Tongliang
    Han, Bo
    PROCEEDINGS OF THE 28TH ACM SIGKDD CONFERENCE ON KNOWLEDGE DISCOVERY AND DATA MINING, KDD 2022, 2022, : 1358 - 1367
  • [35] Improving Robustness to Model Inversion Attacks via Mutual Information Regularization
    Wang, Tianhao
    Zhang, Yuheng
    Jia, Ruoxi
    THIRTY-FIFTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, THIRTY-THIRD CONFERENCE ON INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE AND THE ELEVENTH SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2021, 35 : 11666 - 11673
  • [36] RVE-PFL: Robust Variational Encoder-Based Personalized Federated Learning Against Model Inversion Attacks
    Issa, Wael
    Moustafa, Nour
    Turnbull, Benjamin
    Choo, Kim-Kwang Raymond
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 3772 - 3787
  • [37] Towards Remediating DDoS Attacks
    Lavrenovs, Arturs
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON CYBER WARFARE AND SECURITY (ICCWS 2021), 2021, : 152 - 158
  • [38] Towards Defeating DDoS Attacks
    Doyal, Alex
    Zhan, Justin
    Yu, Huiming Anna
    2012 ASE INTERNATIONAL CONFERENCE ON CYBER SECURITY (CYBERSECURITY), 2012, : 209 - 212
  • [39] Robust coalitional model predictive control with plug-and-play capabilities
    Masero, Eva
    Baldivieso-Monasterios, Pablo R.
    Maestre, Jose M.
    Trodden, Paul A.
    AUTOMATICA, 2023, 153
  • [40] Denial-of-Service or Fine-Grained Control: Towards Flexible Model Poisoning Attacks on Federated Learning
    Zhang, Hangtao
    Yao, Zeming
    Zhang, Leo Yu
    Hu, Shengshan
    Chen, Chao
    Liew, Alan
    Li, Zhetao
    PROCEEDINGS OF THE THIRTY-SECOND INTERNATIONAL JOINT CONFERENCE ON ARTIFICIAL INTELLIGENCE, IJCAI 2023, 2023, : 4567 - 4575