{"id":"https://openalex.org/W4392450548","doi":"https://doi.org/10.1109/tifs.2024.3372815","title":"Unstoppable Attack: Label-Only Model Inversion Via Conditional Diffusion Model","display_name":"Unstoppable Attack: Label-Only Model Inversion Via Conditional Diffusion Model","publication_year":2024,"publication_date":"2024-01-01","ids":{"openalex":"https://openalex.org/W4392450548","doi":"https://doi.org/10.1109/tifs.2024.3372815"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2024.3372815","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2024.3372815","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5066622889","display_name":"R. Liu","orcid":"https://orcid.org/0000-0003-4204-8793"},"institutions":[{"id":"https://openalex.org/I50760025","display_name":"Hangzhou Dianzi University","ror":"https://ror.org/0576gt767","country_code":"CN","type":"education","lineage":["https://openalex.org/I50760025"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Rongke Liu","raw_affiliation_strings":["School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China","institution_ids":["https://openalex.org/I50760025"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5077728036","display_name":"Dong Wang","orcid":"https://orcid.org/0000-0001-9246-204X"},"institutions":[{"id":"https://openalex.org/I50760025","display_name":"Hangzhou Dianzi University","ror":"https://ror.org/0576gt767","country_code":"CN","type":"education","lineage":["https://openalex.org/I50760025"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dong Wang","raw_affiliation_strings":["School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China","institution_ids":["https://openalex.org/I50760025"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100614965","display_name":"Yizhi Ren","orcid":"https://orcid.org/0000-0002-1421-9164"},"institutions":[{"id":"https://openalex.org/I50760025","display_name":"Hangzhou Dianzi University","ror":"https://ror.org/0576gt767","country_code":"CN","type":"education","lineage":["https://openalex.org/I50760025"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yizhi Ren","raw_affiliation_strings":["School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China","institution_ids":["https://openalex.org/I50760025"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100422319","display_name":"Zhen Wang","orcid":"https://orcid.org/0000-0002-3399-5281"},"institutions":[{"id":"https://openalex.org/I50760025","display_name":"Hangzhou Dianzi University","ror":"https://ror.org/0576gt767","country_code":"CN","type":"education","lineage":["https://openalex.org/I50760025"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhen Wang","raw_affiliation_strings":["School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China","institution_ids":["https://openalex.org/I50760025"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5094067157","display_name":"Kaitian Guo","orcid":null},"institutions":[{"id":"https://openalex.org/I50760025","display_name":"Hangzhou Dianzi University","ror":"https://ror.org/0576gt767","country_code":"CN","type":"education","lineage":["https://openalex.org/I50760025"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kaitian Guo","raw_affiliation_strings":["School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China","institution_ids":["https://openalex.org/I50760025"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5094067158","display_name":"Qianqian Qin","orcid":null},"institutions":[{"id":"https://openalex.org/I50760025","display_name":"Hangzhou Dianzi University","ror":"https://ror.org/0576gt767","country_code":"CN","type":"education","lineage":["https://openalex.org/I50760025"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qianqian Qin","raw_affiliation_strings":["School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"School of Cyberspace, Hangzhou Dianzi University, Hangzhou, China","institution_ids":["https://openalex.org/I50760025"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100442739","display_name":"Xiaolei Liu","orcid":"https://orcid.org/0000-0001-8510-4025"},"institutions":[{"id":"https://openalex.org/I2801345734","display_name":"China Academy of Engineering Physics","ror":"https://ror.org/039vqpp67","country_code":"CN","type":"facility","lineage":["https://openalex.org/I2801345734"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaolei Liu","raw_affiliation_strings":["Institute of Computer Application, China Academy of Engineering Physics, Mianyang, China"],"affiliations":[{"raw_affiliation_string":"Institute of Computer Application, China Academy of Engineering Physics, Mianyang, China","institution_ids":["https://openalex.org/I2801345734"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5066622889"],"corresponding_institution_ids":["https://openalex.org/I50760025"],"apc_list":null,"apc_paid":null,"fwci":6.9518,"has_fulltext":false,"cited_by_count":18,"citation_normalized_percentile":{"value":0.97239278,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":100},"biblio":{"volume":"19","issue":null,"first_page":"3958","last_page":"3973"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11206","display_name":"Model Reduction and Neural Networks","score":0.9914000034332275,"subfield":{"id":"https://openalex.org/subfields/3109","display_name":"Statistical and Nonlinear Physics"},"field":{"id":"https://openalex.org/fields/31","display_name":"Physics and Astronomy"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10775","display_name":"Generative Adversarial Networks and Image Synthesis","score":0.9606999754905701,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.73459392786026}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.73459392786026}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2024.3372815","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2024.3372815","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.44999998807907104,"id":"https://metadata.un.org/sdg/13","display_name":"Climate action"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":49,"referenced_works":["https://openalex.org/W1515782956","https://openalex.org/W1576660662","https://openalex.org/W1686810756","https://openalex.org/W1834627138","https://openalex.org/W2024922353","https://openalex.org/W2040008731","https://openalex.org/W2051267297","https://openalex.org/W2112796928","https://openalex.org/W2125389028","https://openalex.org/W2145339207","https://openalex.org/W2194775991","https://openalex.org/W2535690855","https://openalex.org/W2572504188","https://openalex.org/W2757528734","https://openalex.org/W2962785568","https://openalex.org/W2985060393","https://openalex.org/W2985580374","https://openalex.org/W3035616549","https://openalex.org/W3096831136","https://openalex.org/W3107089345","https://openalex.org/W3177170788","https://openalex.org/W4221155076","https://openalex.org/W4226117300","https://openalex.org/W4229820657","https://openalex.org/W4236137412","https://openalex.org/W4288099666","https://openalex.org/W4290948187","https://openalex.org/W4312307529","https://openalex.org/W4313547874","https://openalex.org/W4315784647","https://openalex.org/W4382202942","https://openalex.org/W4382450048","https://openalex.org/W4385245566","https://openalex.org/W4386076307","https://openalex.org/W4387561187","https://openalex.org/W4390774499","https://openalex.org/W6628547770","https://openalex.org/W6637373629","https://openalex.org/W6678815747","https://openalex.org/W6679045638","https://openalex.org/W6684191040","https://openalex.org/W6685777803","https://openalex.org/W6765779288","https://openalex.org/W6779823529","https://openalex.org/W6795288823","https://openalex.org/W6810621514","https://openalex.org/W6840815571","https://openalex.org/W6848734431","https://openalex.org/W6858077343"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W2382290278","https://openalex.org/W4395014643"],"abstract_inverted_index":{"Model":[0],"inversion":[1],"attacks":[2],"(MIAs)":[3],"aim":[4],"to":[5,33,75,125,146,157,176,222],"recover":[6,126],"private":[7],"data":[8],"from":[9,133],"inaccessible":[10],"training":[11,135,159],"sets":[12],"of":[13,81,92,99,208,228],"deep":[14],"learning":[15],"models,":[16],"posing":[17],"a":[18,100,115,120,196,201],"privacy":[19],"threat.":[20],"MIAs":[21,72],"primarily":[22],"focus":[23],"on":[24],"the":[25,34,51,56,64,67,79,82,90,97,107,130,134,147,172,206,223],"white-box":[26],"scenario":[27],"where":[28],"attackers":[29,52],"have":[30],"full":[31],"access":[32],"model\u2019s":[35],"structure":[36],"and":[37,102,151,161,168,178,199,219],"parameters.":[38],"However,":[39],"practical":[40,103],"applications":[41],"are":[42,73,139],"usually":[43],"in":[44,70,86,106],"black-box":[45],"scenarios":[46],"or":[47,60],"label-only":[48,108],"scenarios,":[49],"i.e.,":[50],"can":[53,216],"only":[54],"obtain":[55],"output":[57],"confidence":[58],"vectors":[59],"labels":[61,154],"by":[62],"accessing":[63],"model.":[65],"Therefore,":[66],"attack":[68,104,174],"models":[69],"existing":[71],"difficult":[74],"effectively":[76],"train":[77],"with":[78],"knowledge":[80],"target":[83,131,148,163,224],"model,":[84],"resulting":[85],"sub-optimal":[87],"attacks.":[88],"To":[89],"best":[91],"our":[93],"knowledge,":[94],"we":[95,113],"pioneer":[96],"research":[98],"powerful":[101],"model":[105,123,149,175],"scenario.":[109],"In":[110],"this":[111,214],"paper,":[112],"develop":[114],"novel":[116],"MIA":[117],"method,":[118],"leveraging":[119],"conditional":[121],"diffusion":[122],"(CDM)":[124],"representative":[127],"samples":[128,221],"under":[129],"label":[132],"set.":[136],"Two":[137],"techniques":[138],"introduced:":[140],"selecting":[141],"an":[142],"auxiliary":[143],"dataset":[144],"relevant":[145],"task":[150],"using":[152,189],"predicted":[153],"as":[155,195,200],"conditions":[156],"guide":[158],"CDM;":[160],"inputting":[162],"label,":[164,225],"pre-defined":[165],"guidance":[166],"strength,":[167],"random":[169],"noise":[170],"into":[171],"trained":[173],"generate":[177,217],"correct":[179],"multiple":[180],"results":[181,211],"for":[182,204],"final":[183],"selection.":[184],"This":[185],"method":[186,215],"is":[187],"evaluated":[188],"Learned":[190],"Perceptual":[191],"Image":[192],"Patch":[193],"Similarity":[194],"new":[197],"metric":[198],"judgment":[202],"basis":[203],"deciding":[205],"values":[207],"hyper-parameters.":[209],"Experimental":[210],"show":[212],"that":[213],"similar":[218],"accurate":[220],"outperforming":[226],"generators":[227],"previous":[229],"approaches.":[230]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2024-03-06T00:00:00"}
