{"id":"https://openalex.org/W4367047229","doi":"https://doi.org/10.1145/3543507.3583306","title":"Ginver: Generative Model Inversion Attacks Against Collaborative Inference","display_name":"Ginver: Generative Model Inversion Attacks Against Collaborative Inference","publication_year":2023,"publication_date":"2023-04-26","ids":{"openalex":"https://openalex.org/W4367047229","doi":"https://doi.org/10.1145/3543507.3583306"},"language":"en","primary_location":{"id":"doi:10.1145/3543507.3583306","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3543507.3583306","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2023","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5047890363","display_name":"Yupeng Yin","orcid":"https://orcid.org/0000-0001-9842-6285"},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yupeng Yin","raw_affiliation_strings":["School of Computer Science and Technology, Shandong University, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Shandong University, China","institution_ids":["https://openalex.org/I80143920"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101485671","display_name":"Xianglong Zhang","orcid":"https://orcid.org/0000-0001-7939-6279"},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xianglong Zhang","raw_affiliation_strings":["School of Computer Science and Technology, Shandong University, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Shandong University, China","institution_ids":["https://openalex.org/I80143920"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5033390700","display_name":"Huanle Zhang","orcid":null},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Huanle Zhang","raw_affiliation_strings":["School of Computer Science and Technology, Shandong University, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Shandong University, China","institution_ids":["https://openalex.org/I80143920"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5019839230","display_name":"Feng Li","orcid":"https://orcid.org/0000-0002-3746-2132"},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Feng Li","raw_affiliation_strings":["School of Computer Science and Technology, Shandong University, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Shandong University, China","institution_ids":["https://openalex.org/I80143920"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100397991","display_name":"Yue Yu","orcid":"https://orcid.org/0000-0002-9865-2212"},"institutions":[{"id":"https://openalex.org/I170215575","display_name":"National University of Defense Technology","ror":"https://ror.org/05d2yfz11","country_code":"CN","type":"education","lineage":["https://openalex.org/I170215575"]},{"id":"https://openalex.org/I4210136793","display_name":"Peng Cheng Laboratory","ror":"https://ror.org/03qdqbt06","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210136793"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yue Yu","raw_affiliation_strings":["National University of Defense Technology, China and Peng Cheng Laboratory, China"],"affiliations":[{"raw_affiliation_string":"National University of Defense Technology, China and Peng Cheng Laboratory, China","institution_ids":["https://openalex.org/I170215575","https://openalex.org/I4210136793"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100692490","display_name":"Xiuzhen Cheng","orcid":"https://orcid.org/0000-0001-9998-2398"},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiuzhen Cheng","raw_affiliation_strings":["School of Computer Science and Technology, Shandong University, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Shandong University, China","institution_ids":["https://openalex.org/I80143920"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100703619","display_name":"Pengfei Hu","orcid":"https://orcid.org/0000-0002-7935-886X"},"institutions":[{"id":"https://openalex.org/I80143920","display_name":"Shandong University of Science and Technology","ror":"https://ror.org/04gtjhw98","country_code":"CN","type":"education","lineage":["https://openalex.org/I80143920"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Pengfei Hu","raw_affiliation_strings":["School of Computer Science and Technology, Shandong University, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Shandong University, China","institution_ids":["https://openalex.org/I80143920"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":7,"corresponding_author_ids":["https://openalex.org/A5047890363"],"corresponding_institution_ids":["https://openalex.org/I80143920"],"apc_list":null,"apc_paid":null,"fwci":2.4355,"has_fulltext":false,"cited_by_count":14,"citation_normalized_percentile":{"value":0.90889042,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"2122","last_page":"2131"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10927","display_name":"Access Control and Trust","score":0.9973000288009644,"subfield":{"id":"https://openalex.org/subfields/3312","display_name":"Sociology and Political Science"},"field":{"id":"https://openalex.org/fields/33","display_name":"Social Sciences"},"domain":{"id":"https://openalex.org/domains/2","display_name":"Social Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9955000281333923,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6896013021469116},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.6813757419586182},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.6554566025733948},{"id":"https://openalex.org/keywords/generative-grammar","display_name":"Generative grammar","score":0.6397264003753662},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3694537281990051},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.33013156056404114},{"id":"https://openalex.org/keywords/geology","display_name":"Geology","score":0.1821022927761078},{"id":"https://openalex.org/keywords/seismology","display_name":"Seismology","score":0.05807808041572571}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6896013021469116},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.6813757419586182},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.6554566025733948},{"id":"https://openalex.org/C39890363","wikidata":"https://www.wikidata.org/wiki/Q36108","display_name":"Generative grammar","level":2,"score":0.6397264003753662},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3694537281990051},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.33013156056404114},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.1821022927761078},{"id":"https://openalex.org/C165205528","wikidata":"https://www.wikidata.org/wiki/Q83371","display_name":"Seismology","level":1,"score":0.05807808041572571},{"id":"https://openalex.org/C77928131","wikidata":"https://www.wikidata.org/wiki/Q193343","display_name":"Tectonics","level":2,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3543507.3583306","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3543507.3583306","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the ACM Web Conference 2023","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.7599999904632568,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2149525673","display_name":null,"funder_award_id":"62202276, 62232010, 62072278","funder_id":"https://openalex.org/F4320334062","funder_display_name":"National Natural Science Foundation of China-Liaoning Joint Fund"},{"id":"https://openalex.org/G5385193388","display_name":null,"funder_award_id":"2021YFB3100400","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320334062","display_name":"National Natural Science Foundation of China-Liaoning Joint Fund","ror":null},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":30,"referenced_works":["https://openalex.org/W1677182931","https://openalex.org/W1915485278","https://openalex.org/W2001996312","https://openalex.org/W2051267297","https://openalex.org/W2166160300","https://openalex.org/W2194775991","https://openalex.org/W2535690855","https://openalex.org/W2962883027","https://openalex.org/W2964223234","https://openalex.org/W2981114133","https://openalex.org/W2982595342","https://openalex.org/W2983140679","https://openalex.org/W2985580374","https://openalex.org/W2989885118","https://openalex.org/W3083715619","https://openalex.org/W3084432478","https://openalex.org/W3115278118","https://openalex.org/W3124671614","https://openalex.org/W3148714641","https://openalex.org/W3153453329","https://openalex.org/W3171162369","https://openalex.org/W3175613352","https://openalex.org/W3181069167","https://openalex.org/W3199257374","https://openalex.org/W4206426144","https://openalex.org/W4214624153","https://openalex.org/W4225004701","https://openalex.org/W4229820657","https://openalex.org/W4236099117","https://openalex.org/W4288057780"],"related_works":["https://openalex.org/W2961085424","https://openalex.org/W4306674287","https://openalex.org/W4387369504","https://openalex.org/W3046775127","https://openalex.org/W4394896187","https://openalex.org/W3170094116","https://openalex.org/W4386462264","https://openalex.org/W3107602296","https://openalex.org/W4364306694","https://openalex.org/W4312192474"],"abstract_inverted_index":{"Deep":[0],"Learning":[1],"(DL)":[2],"has":[3,170],"been":[4],"widely":[5],"adopted":[6],"in":[7,118],"almost":[8],"all":[9],"domains,":[10],"from":[11,206],"threat":[12],"recognition":[13],"to":[14,35,52,89,94,113],"medical":[15],"diagnosis.":[16],"Albeit":[17],"its":[18],"supreme":[19],"model":[20,69,93,108,128,146,160,167],"accuracy,":[21],"DL":[22,37,54],"imposes":[23],"a":[24,49,76],"heavy":[25],"burden":[26],"on":[27,40,70],"devices":[28],"as":[29,105],"it":[30],"incurs":[31],"overwhelming":[32],"system":[33],"overhead":[34],"execute":[36],"models,":[38,55],"especially":[39],"Internet-of-Things":[41],"(IoT)":[42],"and":[43,74,168,183,190,194],"edge":[44],"devices.":[45],"Collaborative":[46],"inference":[47,99],"is":[48,101,110,141],"promising":[50],"approach":[51,100],"supporting":[53],"by":[56,130],"which":[57],"the":[58,64,68,82,86,91,95,97,106,122,126,132,135,157,164,171,186,207],"data":[59,103],"owner":[60],"(the":[61,79],"victim)":[62],"runs":[63,81],"first":[65],"layers":[66,84],"of":[67,85,134,185],"her":[71],"local":[72,137,188],"device":[73],"then":[75],"cloud":[77],"provider":[78],"adversary)":[80],"remaining":[83],"model.":[87,138],"Compared":[88],"offloading":[90],"entire":[92],"cloud,":[96],"collaborative":[98,150],"more":[102],"privacy-preserving":[104],"owner\u2019s":[107],"input":[109,129],"not":[111],"exposed":[112],"outsiders.":[114],"However,":[115],"we":[116],"show":[117,200],"this":[119],"paper":[120],"that":[121,201],"adversary":[123],"can":[124,155],"restore":[125],"victim\u2019s":[127,136,158,187],"exploiting":[131],"output":[133],"Our":[139],"attack":[140,166],"dubbed":[142],"Ginver":[143,154,177,202],"1:":[144],"Generative":[145],"inversion":[147,165],"attacks":[148],"against":[149],"inference.":[151],"Once":[152],"trained,":[153],"infer":[156],"unseen":[159],"inputs":[161],"without":[162],"remaking":[163],"thus":[169],"generative":[172],"capability.":[173],"We":[174],"extensively":[175],"evaluate":[176],"under":[178],"different":[179],"settings":[180],"(e.g.,":[181,192],"white-box":[182],"black-box":[184],"model)":[189],"applications":[191],"CIFAR10":[193],"FaceScrub":[195],"datasets).":[196],"The":[197],"experimental":[198],"results":[199],"recovers":[203],"high-quality":[204],"images":[205],"victims.":[208]},"counts_by_year":[{"year":2025,"cited_by_count":8},{"year":2024,"cited_by_count":6}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
