arXiv:2410.10177cs.CVcs.CR2024-10被引 2

提出新攻击方法,可从扩散模型中推断人脸身份,揭示数据隐私风险

Identity-Focused Inference and Extraction Attacks on Diffusion Models

  • 聚焦身份级别推断,突破传统成员推理局限
  • 在LFW数据集上对扩散模型攻击成功率高达92%
  • 适合关注生成模型隐私安全的研究者和开发者

扩散模型在生成合成图像中的广泛应用引发了对个人数据(尤其是人脸)未经许可用于训练的担忧。本文提出一种新的身份推断框架,旨在追究模型所有者在训练数据中使用个人身份的责任。与传统成员推理攻击不同,该方法专注于身份层面的推断,提供了数据隐私泄露的新视角。在两个面部图像数据集LFW和CelebA上的全面评估表明,所提成员推理攻击优于基线方法,最高攻击成功率达89%,AUC-ROC达0.91;身份推断攻击在基于LFW训练的LDM模型上达到92%准确率;数据提取攻击在DDPM模型上实现91.6%的准确率,验证了该方法在各类扩散模型中的有效性。

原文摘要 · Abstract (English)

The increasing reliance on diffusion models for generating synthetic images has amplified concerns about the unauthorized use of personal data, particularly facial images, in model training. In this paper, we introduce a novel identity inference framework to hold model owners accountable for including individuals' identities in their training data. Our approach moves beyond traditional membership inference attacks by focusing on identity-level inference, providing a new perspective on data privacy violations. Through comprehensive evaluations on two facial image datasets, Labeled Faces in the Wild (LFW) and CelebA, our experiments demonstrate that the proposed membership inference attack surpasses baseline methods, achieving an attack success rate of up to 89% and an AUC-ROC of 0.91, while the identity inference attack attains 92% on LDM models trained on LFW, and the data extraction attack achieves 91.6% accuracy on DDPMs, validating the effectiveness of our approach across diffusion models.

扩散模型身份推断隐私安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。