From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Li, Ziang, Zhang, Hongguang, Wang, Juan, Chen, Meihui, Hu, Hongxin, Yi, Wenzhe, Xu, Xiaoyang, Yang, Mengda, Ma, Chenjun
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910886509150208
author Li, Ziang
Zhang, Hongguang
Wang, Juan
Chen, Meihui
Hu, Hongxin
Yi, Wenzhe
Xu, Xiaoyang
Yang, Mengda
Ma, Chenjun
author_facet Li, Ziang
Zhang, Hongguang
Wang, Juan
Chen, Meihui
Hu, Hongxin
Yi, Wenzhe
Xu, Xiaoyang
Yang, Mengda
Ma, Chenjun
contents Model Inversion Attacks (MIAs) aim to reconstruct private training data from models, leading to privacy leakage, particularly in facial recognition systems. Although many studies have enhanced the effectiveness of white-box MIAs, less attention has been paid to improving efficiency and utility under limited attacker capabilities. Existing black-box MIAs necessitate an impractical number of queries, incurring significant overhead. Therefore, we analyze the limitations of existing MIAs and introduce Surrogate Model-based Inversion with Long-tailed Enhancement (SMILE), a high-resolution oriented and query-efficient MIA for the black-box setting. We begin by analyzing the initialization of MIAs from a data distribution perspective and propose a long-tailed surrogate training method to obtain high-quality initial points. We then enhance the attack's effectiveness by employing the gradient-free black-box optimization algorithm selected by NGOpt. Our experiments show that SMILE outperforms existing state-of-the-art black-box MIAs while requiring only about 5% of the query overhead.
format Preprint
id arxiv_https___arxiv_org_abs_2503_16266
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed Learning
Li, Ziang
Zhang, Hongguang
Wang, Juan
Chen, Meihui
Hu, Hongxin
Yi, Wenzhe
Xu, Xiaoyang
Yang, Mengda
Ma, Chenjun
Cryptography and Security
Model Inversion Attacks (MIAs) aim to reconstruct private training data from models, leading to privacy leakage, particularly in facial recognition systems. Although many studies have enhanced the effectiveness of white-box MIAs, less attention has been paid to improving efficiency and utility under limited attacker capabilities. Existing black-box MIAs necessitate an impractical number of queries, incurring significant overhead. Therefore, we analyze the limitations of existing MIAs and introduce Surrogate Model-based Inversion with Long-tailed Enhancement (SMILE), a high-resolution oriented and query-efficient MIA for the black-box setting. We begin by analyzing the initialization of MIAs from a data distribution perspective and propose a long-tailed surrogate training method to obtain high-quality initial points. We then enhance the attack's effectiveness by employing the gradient-free black-box optimization algorithm selected by NGOpt. Our experiments show that SMILE outperforms existing state-of-the-art black-box MIAs while requiring only about 5% of the query overhead.
title From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed Learning
topic Cryptography and Security
url https://arxiv.org/abs/2503.16266