用扩散模型从神经网络特征逆推图像,提升隐私安全研究效果。
Unlocking Visual Secrets: Inverting Features with Diffusion Priors for Image Reconstruction
- 以扩散模型为先验,逆向重构深层网络提取的图像特征。
- 相比传统方法,重建图像质量显著提升,保留更多细节。
- 适合关注模型隐私泄露与安全防护的研究者参考。
深度神经网络(DNN)中视觉表征的逆向问题在深度学习安全与隐私领域具有重要挑战性。核心目标是从预训练DNN生成的未知目标图像特征中还原原始图像。特征逆向对理解当前分片DNN执行中的隐私泄露问题,以及基于提取特征的应用具有重要意义。本文探索利用扩散模型这一前沿图像生成技术,提升特征逆向质量,并研究引入文本提示与跨帧时间相关性等先验知识的潜力。实验表明,扩散模型能有效挖掘DNN特征中的隐含信息,相比以往方法实现更优的重建性能。本研究为依赖DNN特征的应用在隐私与安全方面的改进提供了重要洞见。
原文摘要 · Abstract (English)
Inverting visual representations within deep neural networks (DNNs) presents a challenging and important problem in the field of security and privacy for deep learning. The main goal is to invert the features of an unidentified target image generated by a pre-trained DNN, aiming to reconstruct the original image. Feature inversion holds particular significance in understanding the privacy leakage inherent in contemporary split DNN execution techniques, as well as in various applications based on the extracted DNN features. In this paper, we explore the use of diffusion models, a promising technique for image synthesis, to enhance feature inversion quality. We also investigate the potential of incorporating alternative forms of prior knowledge, such as textual prompts and cross-frame temporal correlations, to further improve the quality of inverted features. Our findings reveal that diffusion models can effectively leverage hidden information from the DNN features, resulting in superior reconstruction performance compared to previous methods. This research offers valuable insights into how diffusion models can enhance privacy and security within applications that are reliant on DNN features.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。