• Home
  • Search
  • Distributional Black-Box Model Inversion Attack With Multi-Agent Reinforcement Learning
  • https://doi.org/10.1109/tifs.2025.3564043Copy DOI Icon

Distributional Black-Box Model Inversion Attack With Multi-Agent Reinforcement Learning

  • Abstract
  • Literature Map
  • References
  • Similar Papers
Abstract

Model Inversion (MI) attacks based on Generative Adversarial Networks (GAN) aim to recover private training data from complex deep learning models by searching codes in the latent space. However, this method merely searches in a deterministic latent space, resulting in suboptimal latent codes. Additionally, existing distributional MI schemes assume that an attacker can access the structures and parameters of the target model, which is not always feasible in practice. To address these limitations, this paper proposes a novel Distributional Black-Box Model Inversion (DBB-MI) attack by constructing a probabilistic latent space for searching private data. Specifically, DBB-MI does not require the target model’s parameters or specialized GAN training. Instead, it identifies the latent probability distribution by integrating the output of the target model with multi-agent reinforcement learning techniques. Then, it randomly selects latent codes from the latent probability distribution to uncover private data. As the latent probability distribution closely mirrors the target privacy data in the latent space, the recovered data effectively leaks the privacy of the target model’s training samples. Extensive experiments conducted on diverse datasets and networks demonstrate that our DBB-MI outperforms state-of-the-art MI attacks in terms of attack accuracy, K-nearest neighbor feature distance, and peak signal-to-noise ratio.

Similar Papers
  • Research Article
  • Citations1

A Sample-Level Evaluation and Generative Framework for Model Inversion Attacks

  • Apr 11, 2025
  • Proceedings of the AAAI Conference on Artificial Intelligence
  • Haoyang Li +6
  • Research Article

Unknown-Aware Bilateral Dependency Optimization for Defending Against Model Inversion Attacks.

  • Aug 01, 2025
  • IEEE transactions on pattern analysis and machine intelligence
  • Xiong Peng +6
  • Research Article

Non-orthogonal Coding Against Information Leakage in Image Semantic Communication Systems

  • Jan 01, 2026
  • IEEE Communications Letters
  • Linlin Xiao +5
  • Conference Article
  • Citations23

Broadening Differential Privacy for Deep Learning Against Model Inversion Attacks

  • Dec 10, 2020
  • Qiuchen Zhang +4
  • Conference Article
  • Citations50

Privacy Preserving Facial Recognition Against Model Inversion Attacks

  • Dec 01, 2020
  • Pavana Prakash +5
  • Research Article

Adaptive Generative Model Inversion Attacks in Edge-Cloud Collaborative Inference Systems

  • Jan 01, 2026
  • IEEE Transactions on Mobile Computing
  • Haoyu Liu +2
  • PDF
  • Research Article
  • Citations249

Algorithms that remember: model inversion attacks and data protection law.

  • Oct 15, 2018
  • Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences
  • Michael Veale +2
  • Research Article

Federated learning in edge AI: a systematic review of applications, privacy challenges, and preservation techniques

  • Nov 01, 2025
  • Indonesian Journal of Electrical Engineering and Computer Science
  • Christina Thankam Sajan +2
  • Conference Article
  • Citations7

Discovering Density-Preserving Latent Space Walks in GANs for Semantic Image Transformations

  • Oct 17, 2021
  • Guanyue Li +6
  • Conference Article
  • Citations23

FL-PATE: Differentially Private Federated Learning with Knowledge Transfer

  • Dec 01, 2021
  • Yanghe Pan +2
  • Research Article
  • Citations33

Toward Industrial Private AI: A Two-Tier Framework for Data and Model Security

  • Apr 01, 2022
  • IEEE Wireless Communications
  • Sunder Ali Khowaja +4
  • Conference Article
  • Citations89

DivCo: Diverse Conditional Image Synthesis via Contrastive Generative Adversarial Network

  • Jun 01, 2021
  • Rui Liu +4
  • Research Article
  • Citations15

HSGAN: Reducing mode collapse in GANs by the latent code distance of homogeneous samples

  • Nov 18, 2021
  • Computer Vision and Image Understanding
  • Simin Yu +5
  • Research Article

Privacy-Preserving V2X Federated Learning with Local Filtering for Sustainable Digital Last-mile Logistics

  • Jan 01, 2026
  • Journal of Business Management and Economic Development
  • Nguyen The Huan
  • Conference Article
  • Citations6

Privacy Risk Assessment of Training Data in Machine Learning

  • May 16, 2022
  • Yang Bai +3
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.