arXiv:2411.16458cs.LG2024-11

研究如何从群不变神经网络中还原训练数据,揭示了传统方法的局限性。

On the Reconstruction of Training Data from Group Invariant Networks

  • 提出新方法应对群不变网络的数据重建难题
  • 发现传统方法重建结果多为对称输入,质量差
  • 适合关注模型隐私与可解释性的研究者

从已训练的神经网络中重构训练数据是隐私和可解释性领域的重要研究方向。近期工作已证明多种数据类型的可行性,但针对群不变神经网络的数据重建仍面临独特挑战且鲜有研究。本文首先形式化该问题并分析其基本性质,随后通过实验表明,传统重建技术在此场景下表现不佳:重构结果趋向于群作用平凡的对称输入,导致质量低下。最后,我们提出两种新方法以改善此类设置下的重建效果,并展示初步有前景的实验结果。本工作揭示了群不变网络数据重建的复杂性,为未来研究提供了新路径。

原文摘要 · Abstract (English)

Reconstructing training data from trained neural networks is an active area of research with significant implications for privacy and explainability. Recent advances have demonstrated the feasibility of this process for several data types. However, reconstructing data from group-invariant neural networks poses distinct challenges that remain largely unexplored. This paper addresses this gap by first formulating the problem and discussing some of its basic properties. We then provide an experimental evaluation demonstrating that conventional reconstruction techniques are inadequate in this scenario. Specifically, we observe that the resulting data reconstructions gravitate toward symmetric inputs on which the group acts trivially, leading to poor-quality results. Finally, we propose two novel methods aiming to improve reconstruction in this setup and present promising preliminary experimental results. Our work sheds light on the complexities of reconstructing data from group invariant neural networks and offers potential avenues for future research in this domain.

数据重建神经网络隐私群不变

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。