中文

针对微调潜在扩散模型的人脸图像成员推断攻击

计算机视觉与模式识别 2025-03-05 v1

摘要

生成式图像模型的兴起引发了关于用于训练此类模型的大型数据集的隐私问题。本文探讨了推断特定人脸图像集是否用于微调潜在扩散模型 (LDM) 的可能性。本文提出一种针对此任务的成员推断攻击 (MIA) 方法。使用生成的辅助数据训练攻击模型可显著提升性能,水印的使用也具有类似效果。研究发现,推理时使用的指导比例对攻击效果有显著影响。如果 LDM 微调时间足够长,则用于推理的文本提示对攻击效果影响不大。我们的方法在针对基于人脸图像微调的 LDM 的现实黑盒设置下被证明是可行的。

关键词

引用

@article{arxiv.2502.11619,
  title  = {Membership Inference Attacks for Face Images Against Fine-Tuned Latent Diffusion Models},
  author = {Lauritz Christian Holme and Anton Mosquera Storgaard and Siavash Arjomand Bigdeli},
  journal= {arXiv preprint arXiv:2502.11619},
  year   = {2025}
}

备注

In Proceedings of the 20th International Joint Conference on Computer Vision, Imaging and Computer Graphics Theory and Applications (VISIGRAPP 2025) - Volume 2: VISAPP, pages 439-446