{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/adversarial-neural-network-inversion-via","title":"Adversarial Neural Network Inversion via Auxiliary Knowledge Alignment","arxiv_id":"1902.08552","date":"2019-02-22","proceeding":null,"authors":["Ziqi Yang","Ee-Chien Chang","Zhenkai Liang"],"abstract":"The rise of deep learning technique has raised new privacy concerns about the\ntraining data and test data. In this work, we investigate the model inversion\nproblem in the adversarial settings, where the adversary aims at inferring\ninformation about the target model's training data and test data from the\nmodel's prediction values. We develop a solution to train a second neural\nnetwork that acts as the inverse of the target model to perform the inversion.\nThe inversion model can be trained with black-box accesses to the target model.\nWe propose two main techniques towards training the inversion model in the\nadversarial settings. First, we leverage the adversary's background knowledge\nto compose an auxiliary set to train the inversion model, which does not\nrequire access to the original training data. Second, we design a\ntruncation-based technique to align the inversion model to enable effective\ninversion of the target model from partial predictions that the adversary\nobtains on victim user's data. We systematically evaluate our inversion\napproach in various machine learning tasks and model architectures on multiple\nimage datasets. Our experimental results show that even with no full knowledge\nabout the target model's training data, and with only partial prediction\nvalues, our inversion approach is still able to perform accurate inversion of\nthe target model, and outperform previous approaches.","url_abs":"http://arxiv.org/abs/1902.08552v1","url_pdf":"http://arxiv.org/pdf/1902.08552v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"adversarial-neural-network-inversion-via","repo_url":"https://github.com/yziqi/adversarial-model-inversion","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1902.08552","mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}