English

Training Data Reconstruction: Privacy due to Uncertainty?

Machine Learning 2024-12-12 v1 Cryptography and Security

Abstract

Being able to reconstruct training data from the parameters of a neural network is a major privacy concern. Previous works have shown that reconstructing training data, under certain circumstances, is possible. In this work, we analyse such reconstructions empirically and propose a new formulation of the reconstruction as a solution to a bilevel optimisation problem. We demonstrate that our formulation as well as previous approaches highly depend on the initialisation of the training images xx to reconstruct. In particular, we show that a random initialisation of xx can lead to reconstructions that resemble valid training samples while not being part of the actual training dataset. Thus, our experiments on affine and one-hidden layer networks suggest that when reconstructing natural images, yet an adversary cannot identify whether reconstructed images have indeed been part of the set of training samples.

Keywords

Cite

@article{arxiv.2412.08544,
  title  = {Training Data Reconstruction: Privacy due to Uncertainty?},
  author = {Christina Runkel and Kanchana Vaishnavi Gandikota and Jonas Geiping and Carola-Bibiane Schönlieb and Michael Moeller},
  journal= {arXiv preprint arXiv:2412.08544},
  year   = {2024}
}
R2 v1 2026-06-28T20:31:14.301Z