{"id":"https://openalex.org/W4386076307","doi":"https://doi.org/10.1109/cvpr52729.2023.01964","title":"Reinforcement Learning-Based Black-Box Model Inversion Attacks","display_name":"Reinforcement Learning-Based Black-Box Model Inversion Attacks","publication_year":2023,"publication_date":"2023-06-01","ids":{"openalex":"https://openalex.org/W4386076307","doi":"https://doi.org/10.1109/cvpr52729.2023.01964"},"language":"en","primary_location":{"id":"doi:10.1109/cvpr52729.2023.01964","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52729.2023.01964","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5010223902","display_name":"Gyojin Han","orcid":"https://orcid.org/0009-0002-7905-0045"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":true,"raw_author_name":"Gyojin Han","raw_affiliation_strings":["School of Electrical Engineering, KAIST"],"affiliations":[{"raw_affiliation_string":"School of Electrical Engineering, KAIST","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036667581","display_name":"Jaehyun Choi","orcid":"https://orcid.org/0000-0002-4883-2573"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Jaehyun Choi","raw_affiliation_strings":["School of Electrical Engineering, KAIST"],"affiliations":[{"raw_affiliation_string":"School of Electrical Engineering, KAIST","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5022712207","display_name":"Haeil Lee","orcid":null},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Haeil Lee","raw_affiliation_strings":["School of Electrical Engineering, KAIST"],"affiliations":[{"raw_affiliation_string":"School of Electrical Engineering, KAIST","institution_ids":["https://openalex.org/I157485424"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100606266","display_name":"Junmo Kim","orcid":"https://orcid.org/0000-0002-7174-7932"},"institutions":[{"id":"https://openalex.org/I157485424","display_name":"Korea Advanced Institute of Science and Technology","ror":"https://ror.org/05apxxy63","country_code":"KR","type":"education","lineage":["https://openalex.org/I157485424"]}],"countries":["KR"],"is_corresponding":false,"raw_author_name":"Junmo Kim","raw_affiliation_strings":["School of Electrical Engineering, KAIST"],"affiliations":[{"raw_affiliation_string":"School of Electrical Engineering, KAIST","institution_ids":["https://openalex.org/I157485424"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5010223902"],"corresponding_institution_ids":["https://openalex.org/I157485424"],"apc_list":null,"apc_paid":null,"fwci":5.319,"has_fulltext":false,"cited_by_count":31,"citation_normalized_percentile":{"value":0.96564943,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"20504","last_page":"20513"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.9672999978065491,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/reinforcement-learning","display_name":"Reinforcement learning","score":0.8326507806777954},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8156521320343018},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.6648074984550476},{"id":"https://openalex.org/keywords/adversarial-machine-learning","display_name":"Adversarial machine learning","score":0.6559033393859863},{"id":"https://openalex.org/keywords/white-box","display_name":"White box","score":0.6417484283447266},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.622516930103302},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.580153226852417},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5486895442008972},{"id":"https://openalex.org/keywords/black-box","display_name":"Black box","score":0.5475533604621887},{"id":"https://openalex.org/keywords/markov-decision-process","display_name":"Markov decision process","score":0.48327237367630005},{"id":"https://openalex.org/keywords/markov-process","display_name":"Markov process","score":0.38040217757225037}],"concepts":[{"id":"https://openalex.org/C97541855","wikidata":"https://www.wikidata.org/wiki/Q830687","display_name":"Reinforcement learning","level":2,"score":0.8326507806777954},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8156521320343018},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.6648074984550476},{"id":"https://openalex.org/C2778403875","wikidata":"https://www.wikidata.org/wiki/Q20312394","display_name":"Adversarial machine learning","level":3,"score":0.6559033393859863},{"id":"https://openalex.org/C180932941","wikidata":"https://www.wikidata.org/wiki/Q997233","display_name":"White box","level":2,"score":0.6417484283447266},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.622516930103302},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.580153226852417},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5486895442008972},{"id":"https://openalex.org/C94966114","wikidata":"https://www.wikidata.org/wiki/Q29256","display_name":"Black box","level":2,"score":0.5475533604621887},{"id":"https://openalex.org/C106189395","wikidata":"https://www.wikidata.org/wiki/Q176789","display_name":"Markov decision process","level":3,"score":0.48327237367630005},{"id":"https://openalex.org/C159886148","wikidata":"https://www.wikidata.org/wiki/Q176645","display_name":"Markov process","level":2,"score":0.38040217757225037},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C105795698","wikidata":"https://www.wikidata.org/wiki/Q12483","display_name":"Statistics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/cvpr52729.2023.01964","is_oa":false,"landing_page_url":"https://doi.org/10.1109/cvpr52729.2023.01964","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.800000011920929}],"awards":[{"id":"https://openalex.org/G6758007335","display_name":null,"funder_award_id":"2022-0-00184","funder_id":"https://openalex.org/F4320328359","funder_display_name":"Ministry of Science and ICT, South Korea"}],"funders":[{"id":"https://openalex.org/F4320328359","display_name":"Ministry of Science and ICT, South Korea","ror":"https://ror.org/01wpjm123"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":36,"referenced_works":["https://openalex.org/W1473189865","https://openalex.org/W1686810756","https://openalex.org/W1834627138","https://openalex.org/W2024922353","https://openalex.org/W2051267297","https://openalex.org/W2145339207","https://openalex.org/W2150468603","https://openalex.org/W2158213899","https://openalex.org/W2194775991","https://openalex.org/W2515770085","https://openalex.org/W2780958074","https://openalex.org/W2781726626","https://openalex.org/W2787938642","https://openalex.org/W2962770929","https://openalex.org/W2963864421","https://openalex.org/W2985580374","https://openalex.org/W3034839660","https://openalex.org/W3035616549","https://openalex.org/W3048684575","https://openalex.org/W3212332209","https://openalex.org/W4226117300","https://openalex.org/W4229820657","https://openalex.org/W4298201312","https://openalex.org/W4302570325","https://openalex.org/W4312307529","https://openalex.org/W4320013936","https://openalex.org/W6628547770","https://openalex.org/W6637373629","https://openalex.org/W6684205842","https://openalex.org/W6684921986","https://openalex.org/W6726453277","https://openalex.org/W6747473740","https://openalex.org/W6748839928","https://openalex.org/W6760759230","https://openalex.org/W6780983157","https://openalex.org/W6803903061"],"related_works":["https://openalex.org/W3048732067","https://openalex.org/W2047881532","https://openalex.org/W4383468834","https://openalex.org/W1984273188","https://openalex.org/W4283221438","https://openalex.org/W2900159906","https://openalex.org/W2727407240","https://openalex.org/W4384648009","https://openalex.org/W4287828318","https://openalex.org/W4224288049"],"abstract_inverted_index":{"Model":[0],"inversion":[1,28,59,107,206],"attacks":[2,29,60],"are":[3],"a":[4,16,80,102,116,201],"type":[5],"of":[6,47,75,83,91,134,180,193],"privacy":[7],"attack":[8,50,77,174,187],"that":[9,61,172],"reconstructs":[10],"private":[11,146,178],"data":[12,147],"used":[13],"to":[14,35,71,138,141],"train":[15],"machine":[17,197],"learning":[18,198],"model,":[19],"solely":[20],"by":[21,156,184,199],"accessing":[22],"the":[23,53,73,76,88,111,131,135,145,152,157,161,177,181,191],"model.":[24],"Recently,":[25],"white-box":[26,94],"model":[27,58,106,183,205],"leveraging":[30],"Generative":[31],"Adversarial":[32],"Networks":[33],"(GANs)":[34],"distill":[36],"knowledge":[37],"from":[38,65],"public":[39],"datasets":[40,168],"have":[41],"been":[42],"receiving":[43],"great":[44],"attention":[45],"because":[46],"their":[48],"excellent":[49],"performance.":[51,188],"On":[52],"other":[54],"hand,":[55],"current":[56],"black-box":[57,105,204],"utilize":[62],"GANs":[63],"suffer":[64],"issues":[66],"such":[67],"as":[68,93,115],"being":[69],"unable":[70],"guarantee":[72],"completion":[74],"process":[78],"within":[79],"predetermined":[81],"number":[82],"query":[84],"accesses":[85],"or":[86],"achieve":[87],"same":[89],"level":[90],"performance":[92],"attacks.":[95],"To":[96],"overcome":[97],"these":[98],"limitations,":[99],"we":[100],"propose":[101],"reinforcement":[103,126],"learning-based":[104],"attack.":[108,207],"We":[109,189],"formulate":[110],"latent":[112,153],"space":[113],"search":[114],"Markov":[117],"Decision":[118],"Process":[119],"(MDP)":[120],"problem":[121],"and":[122,169],"solve":[123],"it":[124],"with":[125],"learning.":[127],"Our":[128],"method":[129],"utilizes":[130],"confidence":[132],"scores":[133],"generated":[136],"images":[137],"provide":[139],"rewards":[140],"an":[142],"agent.":[143],"Finally,":[144],"can":[148],"be":[149],"reconstructed":[150],"using":[151],"vectors":[154],"found":[155],"agent":[158],"trained":[159],"in":[160],"MDP.":[162],"The":[163],"experiment":[164],"results":[165],"on":[166,195],"various":[167],"models":[170],"demonstrate":[171],"our":[173],"successfully":[175],"recovers":[176],"information":[179],"target":[182],"achieving":[185],"state-of-the-art":[186],"emphasize":[190],"importance":[192],"studies":[194],"privacy-preserving":[196],"proposing":[200],"more":[202],"advanced":[203]},"counts_by_year":[{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":12}],"updated_date":"2026-04-18T07:56:08.524223","created_date":"2025-10-10T00:00:00"}
