首个针对深度哈希的模型逆向攻击框架,揭示其严重隐私漏洞。
Model Inversion Attack Against Deep Hashing
- 基于扩散模型与语义哈希中心引导逆向生成
- 黑盒下仍可还原高分辨率、高质量图像
- 适用于评估深度哈希系统的隐私安全性
深度哈希通过紧凑的二进制编码提升检索效率,但引入了严重且常被忽视的隐私风险。从哈希码重建原始训练数据可能导致生物特征伪造和隐私泄露。然而,针对深度哈希模型的模型逆向攻击尚未被研究,主要因真实训练哈希码不可获取,且高度离散的汉明空间使现有方法难以适用。为此,我们提出DHMI,首个专为深度哈希设计的基于扩散的模型逆向框架。DHMI首先对辅助数据集聚类,提取语义哈希中心作为代理锚点;随后引入代理引导的去噪优化方法,结合分类一致性与哈希相似性构建新攻击指标,动态筛选候选样本;一组代理模型指导候选样本的精炼,确保生成图像兼具高保真度与语义一致性。在多个数据集上的实验表明,即便在最严苛的黑盒设置(无训练哈希码)下,DHMI仍能成功还原高分辨率、高质量图像,性能优于现有最先进的黑盒模型逆向攻击,验证了该方法的有效性及深度哈希系统内在的严重隐私风险。
原文摘要 · Abstract (English)
Deep hashing improves retrieval efficiency through compact binary codes, yet it introduces severe and often overlooked privacy risks. The ability to reconstruct original training data from hash codes could lead to serious threats such as biometric forgery and privacy breaches. However, model inversion attacks specifically targeting deep hashing models remain unexplored, leaving their security implications unexamined. This research gap stems from the inaccessibility of genuine training hash codes and the highly discrete Hamming space, which prevents existing methods from adapting to deep hashing. To address these challenges, we propose DHMI, the first diffusion-based model inversion framework designed for deep hashing. DHMI first clusters an auxiliary dataset to derive semantic hash centers as surrogate anchors. It then introduces a surrogate-guided denoising optimization method that leverages a novel attack metric (fusing classification consistency and hash proximity) to dynamically select candidate samples. A cluster of surrogate models guides the refinement of these candidates, ensuring the generation of high-fidelity and semantically consistent images. Experiments on multiple datasets demonstrate that DHMI successfully reconstructs high-resolution, high-quality images even under the most challenging black-box setting, where no training hash codes are available. Our method outperforms the existing state-of-the-art model inversion attacks in black-box scenarios, confirming both its practical efficacy and the critical privacy risks inherent in deep hashing systems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。