Adaptive Model Inversion Attacks Generalize a Privacy-Robustness Tradeoff

📅 2026-10-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses a critical limitation in existing model inversion attack evaluations, where optimization failures are frequently conflated with genuine privacy protection, thereby severely underestimating leakage risks. We propose an adaptive attack framework that integrates defense mechanisms such as MixUp and adversarial training with external classifiers for quantitative reassessment. This work is the first to demonstrate that adaptive attacks effectively expose previously overlooked privacy vulnerabilities, revealing significant weaknesses in standard defenses against high-resolution image reconstruction. Furthermore, we introduce a novel perspective identifying a generalized trade-off between reconstruction leakage rates and adversarial robustness. Experiments on the FaceScrub dataset show a 1.16- to 6.59-fold increase in measured privacy leakage, validating adversarial robustness as an effective proxy metric for assessing reconstruction vulnerability.
📝 Abstract
In this paper, we show that standard evaluations of high-resolution Model Inversion Attacks (MIAs) significantly underestimate training-data privacy leakage. State-of-the-art privacy defenses, standard training techniques such as MixUp and Adversarial Training, and undefended models all leak training images at rates 1.16 to 6.59 times higher on FaceScrub under simple adaptive changes to the attack, with the largest increases among defenses reporting the strongest privacy. We further show that measured leakage depends on the feature basis of the external classifier used to evaluate reconstructions: for the same reconstructed images, an adversarially trained Inception evaluator identifies the targeted identity at different rates than the standard Inception evaluator. Our results suggest that standard MIA evaluation can mistake optimization and measurement failures for privacy. These underestimated leakage rates also concealed a broader relationship between privacy and adversarial robustness. Once we adapt the attack and vary the evaluator, reconstruction leakage closely tracks adversarial robustness across recent defenses and standard training regimes, suggesting that robustness provides an attack-agnostic proxy for reconstruction vulnerability that applies far more broadly than previously theorized. This raises an open question: can a practical defense reduce training-data reconstruction without paying a corresponding cost in adversarial robustness?
Problem

Research questions and friction points this paper is trying to address.

Model Inversion Attacks
Privacy Leakage
Adversarial Robustness
Evaluation Underestimation
Privacy-Robustness Tradeoff
Innovation

Methods, ideas, or system contributions that make the work stand out.

Model Inversion Attacks
Adaptive Attack
Privacy-Robustness Tradeoff
Evaluation Bias
Adversarial Robustness
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
S
Shailen Smith
Department of Computer Science, Dartmouth College
R
Rasmus Torp
Department of Computer Science, Dartmouth College
Adam Breuer
Adam Breuer
Harvard
Political ScienceComputer Science