Model Inversion (MI) attacks aim to disclose private information about the training data by abusing access to the pre-trained models. These attacks enable adversaries to reconstruct high-fidelity data that closely aligns with the private training data, which has raised significant privacy concerns. Despite the rapid advances in the field, we lack a comprehensive overview of existing MI attacks and defenses. To fill this gap, this paper thoroughly investigates this field and presents a holistic survey. Firstly, our work briefly reviews the traditional MI on machine learning scenarios. We then elaborately analyze and compare numerous recent attacks and defenses on \textbf{D}eep \textbf{N}eural \textbf{N}etworks (DNNs) across multiple modalities and learning tasks.
翻译:模型反转(MI)攻击旨在通过滥用对预训练模型的访问权限,泄露训练数据的隐私信息。这类攻击使攻击者能够重构与私有训练数据高度一致的高保真数据,引发了严重的隐私担忧。尽管该领域发展迅速,但现有研究缺乏对现有MI攻击与防御的全面综述。为填补这一空白,本文系统梳理了该领域,呈现了一份综合性调研。首先,本工作简要回顾了机器学习场景下的传统MI攻击。随后,针对跨多种模态与学习任务的\textbf{深度神经网络}(DNN),我们详尽分析并比较了近年来众多的攻击与防御方法。