arXiv:2511.20592cs.LGcs.CV2025-11被引 3

发现潜在扩散模型记忆不均,通过分析潜空间几何可提升隐私攻击效果。

Latent Diffusion Inversion Requires Understanding the Latent Space

  • 按潜空间维度贡献度排序,识别出易被记忆的特征维度
  • 移除低记忆维度后,隐私攻击性能平均提升1-4% AUROC
  • 适用于评估扩散模型隐私风险,尤其关注潜空间结构的研究者

生成模型中训练数据的恢复(模型反演)在数据域扩散模型中被广泛研究,被视为记忆/过拟合现象。潜在扩散模型(LDMs)基于编码器/解码器对生成的潜在码运行,对先前反演方法表现出鲁棒性。本文揭示两个关键发现:(1) 扩散模型在潜在码上存在非均匀记忆,倾向于过拟合解码器拉回度量中的高失真区域;(2) 即使在单一潜在码内,各表示维度的记忆贡献也不均等。我们提出一种方法,根据维度对解码器拉回度量的贡献进行排序,从而识别出导致记忆的关键维度。针对基于得分的成员推理(模型反演的子任务),发现移除低记忆维度后,在所有测试方法和数据集上性能均提升,包括CIFAR-10、CelebA、ImageNet-1K、Pokemon、MS-COCO和Flickr,平均AUROC提升1-4%,特异度@1%假阳性率(TPR@1%FPR)提升1-32%。结果强调了自动编码器几何结构对LDM记忆的被忽视影响,并为分析扩散生成模型的隐私风险提供了新视角。

原文摘要 · Abstract (English)

The recovery of training data from generative models ("model inversion") has been extensively studied for diffusion models in the data domain as a memorization/overfitting phenomenon. Latent diffusion models (LDMs), which operate on the latent codes from encoder/decoder pairs, have been robust to prior inversion methods. In this work we describe two key findings: (1) the diffusion model exhibits non-uniform memorization across latent codes, tending to overfit samples located in high-distortion regions of the decoder pullback metric; (2) even within a single latent code, memorization contributions are unequal across representation dimensions. Our proposed method to ranks latent dimensions by their contribution to the decoder pullback metric, which in turn identifies dimensions that contribute to memorization. For score-based membership inference, a sub-task of model inversion, we find that removing less-memorizing dimensions improves performance on all tested methods and datasets, with average AUROC gains of 1-4% and substantial increases in TPR@1%FPR (1-32%) across diverse datasets including CIFAR-10, CelebA, ImageNet-1K, Pokemon, MS-COCO, and Flickr. Our results highlight the overlooked influence of the auto-encoder geometry on LDM memorization and provide a new perspective for analyzing privacy risks in diffusion-based generative models.

隐私安全扩散模型潜空间成员推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。