Plug Play Attacks: Towards Robust and Flexible Model Inversion Attacks

01/28/2022
by   Lukas Struppek, et al.
2

Model inversion attacks (MIAs) aim to create synthetic images that reflect the class-wise characteristics from a target classifier's training data by exploiting the model's learned knowledge. Previous research has developed generative MIAs using generative adversarial networks (GANs) as image priors that are tailored to a specific target model. This makes the attacks time- and resource-consuming, inflexible, and susceptible to distributional shifts between datasets. To overcome these drawbacks, we present Plug Play Attacks that loosen the dependency between the target model and image prior and enable the use of a single trained GAN to attack a broad range of targets with only minor attack adjustments needed. Moreover, we show that powerful MIAs are possible even with publicly available pre-trained GANs and under strong distributional shifts, whereas previous approaches fail to produce meaningful results. Our extensive evaluation confirms the improved robustness and flexibility of Plug Play Attacks and their ability to create high-quality images revealing sensitive class characteristics.

READ FULL TEXT

page 3

page 5

page 7

page 8

page 17

page 20

page 21

research
11/17/2019

The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks

This paper studies model-inversion attacks, in which the access to a mod...
research
10/08/2020

Improved Techniques for Model Inversion Attacks

Model inversion (MI) attacks in the whitebox setting are aimed at recons...
research
06/08/2023

Ownership Protection of Generative Adversarial Networks

Generative adversarial networks (GANs) have shown remarkable success in ...
research
10/06/2020

BAAAN: Backdoor Attacks Against Autoencoder and GAN-Based Machine Learning Models

The tremendous progress of autoencoders and generative adversarial netwo...
research
12/22/2022

GAN-based Domain Inference Attack

Model-based attacks can infer training data information from deep neural...
research
11/02/2017

A Classification-Based Perspective on GAN Distributions

A fundamental, and still largely unanswered, question in the context of ...
research
06/11/2022

Bilateral Dependency Optimization: Defending Against Model-inversion Attacks

Through using only a well-trained classifier, model-inversion (MI) attac...

Please sign up or login with your details

Forgot password? Click here to reset