{"id":"https://openalex.org/W4414170383","doi":"https://doi.org/10.1109/avss65446.2025.11149977","title":"Label-Only Model Inversion Attacks with Query-Free Training of Conditional Diffusion-Based Attack Model","display_name":"Label-Only Model Inversion Attacks with Query-Free Training of Conditional Diffusion-Based Attack Model","publication_year":2025,"publication_date":"2025-08-11","ids":{"openalex":"https://openalex.org/W4414170383","doi":"https://doi.org/10.1109/avss65446.2025.11149977"},"language":"en","primary_location":{"id":"doi:10.1109/avss65446.2025.11149977","is_oa":false,"landing_page_url":"https://doi.org/10.1109/avss65446.2025.11149977","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Advanced Visual and Signal-Based Systems (AVSS)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":null,"display_name":"Hikaru Mori","orcid":null},"institutions":[{"id":"https://openalex.org/I161296585","display_name":"Tokyo University of Science","ror":"https://ror.org/05sj3n476","country_code":"JP","type":"education","lineage":["https://openalex.org/I161296585"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Hikaru Mori","raw_affiliation_strings":["Tokyo University of Science,Tokyo,Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tokyo University of Science,Tokyo,Japan","institution_ids":["https://openalex.org/I161296585"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5058191809","display_name":"Kazuaki Nakamura","orcid":"https://orcid.org/0000-0002-4859-4624"},"institutions":[{"id":"https://openalex.org/I161296585","display_name":"Tokyo University of Science","ror":"https://ror.org/05sj3n476","country_code":"JP","type":"education","lineage":["https://openalex.org/I161296585"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Kazuaki Nakamura","raw_affiliation_strings":["Tokyo University of Science,Tokyo,Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Tokyo University of Science,Tokyo,Japan","institution_ids":["https://openalex.org/I161296585"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.1135499,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9908999800682068,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/attack-model","display_name":"Attack model","score":0.6383000016212463},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.633400022983551},{"id":"https://openalex.org/keywords/image","display_name":"Image (mathematics)","score":0.5310999751091003},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.47279998660087585},{"id":"https://openalex.org/keywords/feature","display_name":"Feature (linguistics)","score":0.4562000036239624},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.45210000872612},{"id":"https://openalex.org/keywords/class","display_name":"Class (philosophy)","score":0.4438999891281128},{"id":"https://openalex.org/keywords/training-set","display_name":"Training set","score":0.4341999888420105}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6759999990463257},{"id":"https://openalex.org/C65856478","wikidata":"https://www.wikidata.org/wiki/Q3991682","display_name":"Attack model","level":2,"score":0.6383000016212463},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.633400022983551},{"id":"https://openalex.org/C115961682","wikidata":"https://www.wikidata.org/wiki/Q860623","display_name":"Image (mathematics)","level":2,"score":0.5310999751091003},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4878000020980835},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.47279998660087585},{"id":"https://openalex.org/C2776401178","wikidata":"https://www.wikidata.org/wiki/Q12050496","display_name":"Feature (linguistics)","level":2,"score":0.4562000036239624},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.45210000872612},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.4438999891281128},{"id":"https://openalex.org/C51632099","wikidata":"https://www.wikidata.org/wiki/Q3985153","display_name":"Training set","level":2,"score":0.4341999888420105},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.40709999203681946},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.396699994802475},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3878999948501587},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.3377000093460083},{"id":"https://openalex.org/C2777211547","wikidata":"https://www.wikidata.org/wiki/Q17141490","display_name":"Training (meteorology)","level":2,"score":0.3345000147819519},{"id":"https://openalex.org/C52622490","wikidata":"https://www.wikidata.org/wiki/Q1026626","display_name":"Feature extraction","level":2,"score":0.310699999332428},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3028999865055084},{"id":"https://openalex.org/C104122410","wikidata":"https://www.wikidata.org/wiki/Q1416406","display_name":"Network model","level":2,"score":0.29750001430511475},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.29249998927116394},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.28790000081062317},{"id":"https://openalex.org/C117978034","wikidata":"https://www.wikidata.org/wiki/Q5422192","display_name":"Extractor","level":2,"score":0.2815000116825104},{"id":"https://openalex.org/C31972630","wikidata":"https://www.wikidata.org/wiki/Q844240","display_name":"Computer vision","level":1,"score":0.2766999900341034},{"id":"https://openalex.org/C58489278","wikidata":"https://www.wikidata.org/wiki/Q1172284","display_name":"Data set","level":2,"score":0.26930001378059387},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.25270000100135803}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/avss65446.2025.11149977","is_oa":false,"landing_page_url":"https://doi.org/10.1109/avss65446.2025.11149977","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 IEEE International Conference on Advanced Visual and Signal-Based Systems (AVSS)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":13,"referenced_works":["https://openalex.org/W1834627138","https://openalex.org/W2051267297","https://openalex.org/W2624918875","https://openalex.org/W2963839617","https://openalex.org/W3035616549","https://openalex.org/W3159834477","https://openalex.org/W4206426144","https://openalex.org/W4288099666","https://openalex.org/W4312307529","https://openalex.org/W4312402191","https://openalex.org/W4313547874","https://openalex.org/W4384519404","https://openalex.org/W4392450548"],"related_works":[],"abstract_inverted_index":{"As":[0],"DNN-based":[1],"AI":[2],"models":[3,266],"have":[4,126],"rapidly":[5],"developed,":[6],"the":[7,26,41,54,101,114,120,135,161,174,202,236,243],"risk":[8],"of":[9,56,132,220,222,270],"cyber-attacks":[10],"against":[11],"them":[12],"has":[13],"also":[14],"increased.":[15],"This":[16],"paper":[17],"focuses":[18],"on":[19],"Model":[20,171],"Inversion":[21],"Attacks":[22],"(MIA),":[23],"which":[24,140],"is":[25,65,89,141],"attack":[27,162,175,180,215,248],"to":[28,44,79,90,118,127,134,159,177,197,206,251],"reveal":[29],"a":[30,60,68,87,129,151,168,207,213,218],"victim":[31,42,69,115,136,237],"model\u2019s":[32],"training":[33,230],"data":[34],"by":[35,100,113],"estimating":[36],"input":[37],"samples":[38],"that":[39,155,242,256,267],"causes":[40],"model":[43,64,70,88,95,137,176,216],"produce":[45],"adversaries\u2019":[46,102,203],"designated":[47],"output.":[48],"Modern":[49],"MIA":[50,153,253,257],"methods":[51,125],"often":[52],"tackle":[53],"task":[55],"Label-Only":[57,152],"MIA,":[58],"where":[59],"black-box":[61],"image":[62,93,104,187,224,264],"classification":[63,265],"assumed":[66],"as":[67,138,173,190],"whose":[71],"network":[72],"structure":[73],"and":[74,106,194,225],"parameters":[75],"are":[76,232,259,268],"not":[77],"disclosed":[78],"adversaries.":[80],"A":[81],"key":[82],"technique":[83],"for":[84,262],"attacking":[85],"such":[86],"exploit":[91],"an":[92,186,191,223,247],"generation":[94],"(called":[96],"\"attack":[97],"model\")":[98],"trained":[99],"own":[103,204],"set":[105,111,219],"its":[107,226],"corresponding":[108],"class":[109,121],"label":[110,122],"provided":[112],"model.":[116,163,238],"However,":[117],"get":[119],"set,":[123],"existing":[124],"send":[128,275],"massive":[130],"amount":[131],"images":[133,200],"queries,":[139],"highly":[142],"suspicious":[143],"behavior.":[144],"To":[145],"solve":[146],"this":[147],"unpracticality,":[148],"we":[149,183,211],"propose":[150],"method":[154,166,245],"requires":[156],"no":[157],"queries":[158],"train":[160,185,212],"The":[164],"proposed":[165,244],"employs":[167],"Conditional":[169],"Diffusion":[170],"(CDM)":[172],"obtain":[178],"plausible":[179],"results.":[181],"Specifically,":[182],"first":[184],"feature":[188,208],"extractor":[189],"auxiliary":[192],"module":[193],"use":[195],"it":[196],"embed":[198],"all":[199],"in":[201],"dataset":[205],"space.":[209],"Then,":[210],"CDM-based":[214],"using":[217],"pairs":[221],"embedded":[227],"feature.":[228],"These":[229],"procedures":[231],"performed":[233],"independently":[234],"from":[235],"We":[239],"experimentally":[240],"confirmed":[241],"achieves":[246],"performance":[249],"comparable":[250],"white-box-oriented":[252],"methods,":[254],"demonstrating":[255],"risks":[258],"significant":[260],"even":[261],"practical":[263],"capable":[269],"blocking":[271],"malicious":[272],"users":[273],"who":[274],"too":[276],"many":[277],"queries.":[278]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
