Current methods for reconstructing training data from trained classifiers are restricted to very small models, limited training set sizes, and low-resolution images. Such restrictions hinder their applicability to real-world scenarios. In this paper, we present a novel approach enabling data reconstruction in realistic settings for models trained on high-resolution images. Our method adapts the reconstruction scheme of arXiv:2206.07758 to real-world scenarios -- specifically, targeting models trained via transfer learning over image embeddings of large pre-trained models like DINO-ViT and CLIP. Our work employs data reconstruction in the embedding space rather than in the image space, showcasing its applicability beyond visual data. Moreover, we introduce a novel clustering-based method to identify good reconstructions from thousands of candidates. This significantly improves on previous works that relied on knowledge of the training set to identify good reconstructed images. Our findings shed light on a potential privacy risk for data leakage from models trained using transfer learning.
翻译:当前从训练好的分类器中重构训练数据的方法仅限于非常小的模型、有限的训练集规模和低分辨率图像。这些限制阻碍了其在真实世界场景中的适用性。本文提出一种新颖方法,能够在高分辨率图像训练模型的实际场景中实现数据重构。我们的方法将arXiv:2206.07758的重构方案适配到真实世界场景——具体针对通过DINO-ViT和CLIP等大型预训练模型的图像嵌入进行迁移学习训练的模型。本工作在嵌入空间而非图像空间进行数据重构,展示了其超越视觉数据的适用性。此外,我们引入了一种基于聚类的新方法,可从数千个候选重构中识别优质重构。这显著改进了以往依赖训练集先验知识来识别优质重构图像的方法。我们的研究揭示了迁移学习训练模型存在数据泄露的潜在隐私风险。