{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/arxiv-2607-12354","title":"Reducing information dependency does not cause training data privacy. Adversarially non-robust features do","arxiv_id":"2607.12354","date":"2026-07-14","proceeding":null,"authors":["Rasmus Torp","Shailen K. Smith","Adam Breuer"],"abstract":"In this paper, we challenge the prevailing view that information dependency (including rote memorization) drives training data exposure to image reconstruction attacks. We show that extensive exposure can persist without rote memorization and is instead caused by a tunable connection to adversarial robustness. We begin by presenting three surprising results: (1) recent defenses that inhibit reconstruction by Model Inversion Attacks (MIAs), which evaluate leakage under an idealized attacker, do not reduce standard measures of information dependency (HSIC); (2) models that maximally memorize their training datasets remain robust to MIA reconstruction; and (3) models trained without seeing 97% of the training pixels, where recent information-theoretic bounds give arbitrarily strong privacy guarantees under standard assumptions, can still be devastatingly reconstructed by MIA. To explain these findings, we provide causal evidence that privacy under MIA arises from what the adversarial examples literature calls ``non-robust'' features (generalizable but imperceptible and unstable features). We further show that recent MIA defenses obtain their privacy improvements by unintentionally shifting models toward such features. To establish this causal relationship, we introduce Anti Adversarial Training (AT-AT), a training regime that intentionally learns non-robust features to obtain both superior reconstruction defense and higher accuracy than state-of-the-art defenses. Our results revise the prevailing understanding of training data exposure and reveal a new privacy-robustness tradeoff.","url_abs":"https://arxiv.org/abs/2607.12354","url_pdf":"https://arxiv.org/pdf/2607.12354","source":{"archive":null,"snapshot":"2025-07-28","note":"not in the Papers with Code archive (frozen at the snapshot)","row_kind":"graph","title_abstract_authors_date":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)"},"code_links":[],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2607.12354","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2607.12354"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"mentioned_in_github":null,"is_official":null,"provenance":"deterministic:regex_extraction","mentioned_in_paper":null,"url":"https://github.com/BreuerLabs/Anti-Adversarial-Training","reach":null}],"summary":{"ran":3,"unverified":1},"by_repo_kind":{"found_in_text":{"samples":4,"ran":3,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":4,"samples":[{"code_sha256_prefix":"b31b8ced23b3b248","entry":"AbstractClassifier","repo":"BreuerLabs/Anti-Adversarial-Training","repo_kind":"found_in_text","path":"defenses/adversarial_train.py","file_url":"https://github.com/BreuerLabs/Anti-Adversarial-Training/blob/HEAD/defenses/adversarial_train.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"b31b8ced23b3b248"}},{"code_sha256_prefix":"539ad170f1881943","entry":"FGSM","repo":"BreuerLabs/Anti-Adversarial-Training","repo_kind":"found_in_text","path":"defenses/adversarial_train.py","file_url":"https://github.com/BreuerLabs/Anti-Adversarial-Training/blob/HEAD/defenses/adversarial_train.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"539ad170f1881943"}},{"code_sha256_prefix":"abbba5e686773648","entry":"PGDAttack","repo":"BreuerLabs/Anti-Adversarial-Training","repo_kind":"found_in_text","path":"defenses/adversarial_train.py","file_url":"https://github.com/BreuerLabs/Anti-Adversarial-Training/blob/HEAD/defenses/adversarial_train.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"abbba5e686773648"}},{"code_sha256_prefix":"08a1b70c9afdb29b","entry":"apply_adversarial_training_defense","repo":"BreuerLabs/Anti-Adversarial-Training","repo_kind":"found_in_text","path":"defenses/adversarial_train.py","file_url":"https://github.com/BreuerLabs/Anti-Adversarial-Training/blob/HEAD/defenses/adversarial_train.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"08a1b70c9afdb29b"}}]},"arxiv_metadata":{"licence":"arXiv metadata, CC0 1.0 (https://info.arxiv.org/help/license)","fields":["title","abstract","authors","date"],"primary_category":"cs.LG","source":"arxiv_2026.jsonl"},"syntology_extracted_results":null}