DiffMI: Breaking Face Recognition Privacy via Diffusion-Driven Training-Free Model Inversion

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wang, Hanrui, Wang, Shuo, Lu, Chun-Shien, Echizen, Isao
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910181715083264
author Wang, Hanrui
Wang, Shuo
Lu, Chun-Shien
Echizen, Isao
author_facet Wang, Hanrui
Wang, Shuo
Lu, Chun-Shien
Echizen, Isao
contents Face recognition poses serious privacy risks due to its reliance on sensitive and immutable biometric data. While modern systems mitigate privacy risks by mapping facial images to embeddings (commonly regarded as privacy-preserving), model inversion attacks reveal that identity information can still be recovered, exposing critical vulnerabilities. However, existing attacks are often computationally expensive and lack generalization, especially those requiring target-specific training. Even training-free approaches suffer from limited identity controllability, hindering faithful reconstruction of nuanced or unseen identities. In this work, we propose DiffMI, the first diffusion-driven, training-free model inversion attack. DiffMI introduces a novel pipeline combining robust latent code initialization, a ranked adversarial refinement strategy, and a statistically grounded, confidence-aware optimization objective. DiffMI applies directly to unseen target identities and face recognition models, offering greater adaptability than training-dependent approaches while significantly reducing computational overhead. Our method achieves 84.42%--92.87% attack success rates against inversion-resilient systems and outperforms the best prior training-free GAN-based approach by 4.01%--9.82%. The implementation is available at https://github.com/azrealwang/DiffMI.
format Preprint
id arxiv_https___arxiv_org_abs_2504_18015
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DiffMI: Breaking Face Recognition Privacy via Diffusion-Driven Training-Free Model Inversion
Wang, Hanrui
Wang, Shuo
Lu, Chun-Shien
Echizen, Isao
Cryptography and Security
Computer Vision and Pattern Recognition
Machine Learning
Face recognition poses serious privacy risks due to its reliance on sensitive and immutable biometric data. While modern systems mitigate privacy risks by mapping facial images to embeddings (commonly regarded as privacy-preserving), model inversion attacks reveal that identity information can still be recovered, exposing critical vulnerabilities. However, existing attacks are often computationally expensive and lack generalization, especially those requiring target-specific training. Even training-free approaches suffer from limited identity controllability, hindering faithful reconstruction of nuanced or unseen identities. In this work, we propose DiffMI, the first diffusion-driven, training-free model inversion attack. DiffMI introduces a novel pipeline combining robust latent code initialization, a ranked adversarial refinement strategy, and a statistically grounded, confidence-aware optimization objective. DiffMI applies directly to unseen target identities and face recognition models, offering greater adaptability than training-dependent approaches while significantly reducing computational overhead. Our method achieves 84.42%--92.87% attack success rates against inversion-resilient systems and outperforms the best prior training-free GAN-based approach by 4.01%--9.82%. The implementation is available at https://github.com/azrealwang/DiffMI.
title DiffMI: Breaking Face Recognition Privacy via Diffusion-Driven Training-Free Model Inversion
topic Cryptography and Security
Computer Vision and Pattern Recognition
Machine Learning
url https://arxiv.org/abs/2504.18015