{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T17:36:29Z","timestamp":1777656989294,"version":"3.51.4"},"publisher-location":"Cham","reference-count":48,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031727634","type":"print"},{"value":"9783031727641","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,10,25]],"date-time":"2024-10-25T00:00:00Z","timestamp":1729814400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,10,25]],"date-time":"2024-10-25T00:00:00Z","timestamp":1729814400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-72764-1_17","type":"book-chapter","created":{"date-parts":[[2024,10,24]],"date-time":"2024-10-24T14:03:10Z","timestamp":1729778590000},"page":"288-306","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Prediction Exposes Your Face: Black-Box Model Inversion via\u00a0Prediction Alignment"],"prefix":"10.1007","author":[{"given":"Yufan","family":"Liu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wanqian","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dayan","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng","family":"Lin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jingzi","family":"Gu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiping","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,10,25]]},"reference":[{"key":"17_CR1","doi-asserted-by":"crossref","unstructured":"Abdal, R., Qin, Y., Wonka, P.: Image2stylegan: how to embed images into the stylegan latent space? In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 4432\u20134441 (2019)","DOI":"10.1109\/ICCV.2019.00453"},{"key":"17_CR2","doi-asserted-by":"crossref","unstructured":"Abdal, R., Qin, Y., Wonka, P.: Image2stylegan++: how to edit the embedded images? In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 8296\u20138305 (2020)","DOI":"10.1109\/CVPR42600.2020.00832"},{"key":"17_CR3","doi-asserted-by":"crossref","unstructured":"Alaluf, Y., Patashnik, O., Cohen-Or, D.: Restyle: a residual-based stylegan encoder via iterative refinement. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 6711\u20136720 (2021)","DOI":"10.1109\/ICCV48922.2021.00664"},{"key":"17_CR4","doi-asserted-by":"crossref","unstructured":"An, J., Zhang, W., Wu, D., Lin, Z., Gu, J., Wang, W.: Sd4privacy: exploiting stable diffusion for protecting facial privacy. In: 2024 IEEE International Conference on Multimedia and Expo (ICME) (2024)","DOI":"10.1109\/ICME57554.2024.10688292"},{"key":"17_CR5","doi-asserted-by":"crossref","unstructured":"An, S., et al.: Mirror: model inversion for deep learning network with high fidelity. In: Proceedings of the 29th Network and Distributed System Security Symposium (2022)","DOI":"10.14722\/ndss.2022.24335"},{"key":"17_CR6","unstructured":"Bau, D., et al.: Semantic photo manipulation with a generative image prior. arXiv preprint arXiv:2005.07727 (2020)"},{"key":"17_CR7","doi-asserted-by":"crossref","unstructured":"Chen, P., Zhang, H., Sharma, Y., Yi, J., Hsieh, C.: ZOO: zeroth order optimization based black-box attacks to deep neural networks without training substitute models. In: AISec@CCS, pp. 15\u201326. ACM (2017)","DOI":"10.1145\/3128572.3140448"},{"key":"17_CR8","doi-asserted-by":"crossref","unstructured":"Chen, S., Kahla, M., Jia, R., Qi, G.J.: Knowledge-enriched distributional model inversion attacks. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 16178\u201316187 (2021)","DOI":"10.1109\/ICCV48922.2021.01587"},{"key":"17_CR9","doi-asserted-by":"crossref","unstructured":"Cheng, Y., et al.: Know you at one glance: a compact vector representation for low-shot learning. In: ICCV Workshops, pp. 1924\u20131932. IEEE Computer Society (2017)","DOI":"10.1109\/ICCVW.2017.227"},{"key":"17_CR10","doi-asserted-by":"crossref","unstructured":"Collins, E., Bala, R., Price, B., Susstrunk, S.: Editing in style: uncovering the local semantics of gans. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 5771\u20135780 (2020)","DOI":"10.1109\/CVPR42600.2020.00581"},{"issue":"7","key":"17_CR11","doi-asserted-by":"publisher","first-page":"1967","DOI":"10.1109\/TNNLS.2018.2875194","volume":"30","author":"A Creswell","year":"2018","unstructured":"Creswell, A., Bharath, A.A.: Inverting the generator of a generative adversarial network. IEEE Trans. Neural Netw. Learn. Syst. 30(7), 1967\u20131974 (2018)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"17_CR12","doi-asserted-by":"crossref","unstructured":"Deng, J., Guo, J., Xue, N., Zafeiriou, S.: Arcface: Additive angular margin loss for deep face recognition. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4690\u20134699 (2019)","DOI":"10.1109\/CVPR.2019.00482"},{"key":"17_CR13","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1322\u20131333 (2015)","DOI":"10.1145\/2810103.2813677"},{"key":"17_CR14","unstructured":"Fredrikson, M., Lantz, E., Jha, S., Lin, S.M., Page, D., Ristenpart, T.: Privacy in pharmacogenetics: an end-to-end case study of personalized warfarin dosing. In: USENIX Security Symposium, pp. 17\u201332. USENIX Association (2014)"},{"key":"17_CR15","doi-asserted-by":"crossref","unstructured":"Gu, J., Shen, Y., Zhou, B.: Image processing using multi-code gan prior. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 3012\u20133021 (2020)","DOI":"10.1109\/CVPR42600.2020.00308"},{"key":"17_CR16","doi-asserted-by":"crossref","unstructured":"Han, G., Choi, J., Lee, H., Kim, J.: Reinforcement learning-based black-box model inversion attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 20504\u201320513 (2023)","DOI":"10.1109\/CVPR52729.2023.01964"},{"key":"17_CR17","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: CVPR, pp. 770\u2013778. IEEE Computer Society (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"17_CR18","doi-asserted-by":"crossref","unstructured":"Kahla, M., Chen, S., Just, H.A., Jia, R.: Label-only model inversion attacks via boundary repulsion. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 15045\u201315053 (2022)","DOI":"10.1109\/CVPR52688.2022.01462"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Kang, K., Kim, S., Cho, S.: Gan inversion for out-of-range images with geometric transformations. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 13941\u201313949 (2021)","DOI":"10.1109\/ICCV48922.2021.01368"},{"key":"17_CR20","doi-asserted-by":"crossref","unstructured":"Karras, T., Laine, S., Aila, T.: A style-based generator architecture for generative adversarial networks. In: CVPR, pp. 4401\u20134410. Computer Vision Foundation\/IEEE (2019)","DOI":"10.1109\/CVPR.2019.00453"},{"key":"17_CR21","doi-asserted-by":"crossref","unstructured":"Karras, T., Laine, S., Aila, T.: A style-based generator architecture for generative adversarial networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 4401\u20134410 (2019)","DOI":"10.1109\/CVPR.2019.00453"},{"key":"17_CR22","doi-asserted-by":"crossref","unstructured":"Liu, H., Song, Y., Chen, Q.: Delving stylegan inversion for image editing: a foundation latent space viewpoint. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 10072\u201310082 (2023)","DOI":"10.1109\/CVPR52729.2023.00971"},{"key":"17_CR23","doi-asserted-by":"crossref","unstructured":"Liu, Y., An, J., Zhang, W., Wu, D., Gu, J., Lin, Z., Wang, W.: Disrupting diffusion: Token-level attention erasure attack against diffusion-based customization. arXiv preprint arXiv:2405.20584 (2024)","DOI":"10.1145\/3664647.3681243"},{"key":"17_CR24","doi-asserted-by":"crossref","unstructured":"Liu, Z., Luo, P., Wang, X., Tang, X.: Deep learning face attributes in the wild. In: Proceedings of the IEEE International Conference on Computer Vision, pp. 3730\u20133738 (2015)","DOI":"10.1109\/ICCV.2015.425"},{"key":"17_CR25","doi-asserted-by":"crossref","unstructured":"Ng, H.W., Winkler, S.: A data-driven approach to cleaning large face datasets. In: 2014 IEEE International Conference on Image Processing (ICIP), pp. 343\u2013347. IEEE (2014)","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"17_CR26","unstructured":"Nguyen, B.N., Chandrasegaran, K., Abdollahzadeh, M., Cheung, N.M.M.: Label-only model inversion attacks via knowledge transfer. Adv. Neural Inform. Process. Syst. 36 (2024)"},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Nguyen, N.B., Chandrasegaran, K., Abdollahzadeh, M., Cheung, N.M.: Re-thinking model inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 16384\u201316393 (2023)","DOI":"10.1109\/CVPR52729.2023.01572"},{"key":"17_CR28","doi-asserted-by":"crossref","unstructured":"Pinto, N., Stone, Z., Zickler, T., Cox, D.: Scaling up biologically-inspired computer vision: a case study in unconstrained face recognition on facebook. In: CVPR 2011 workshops, pp. 35\u201342. IEEE (2011)","DOI":"10.1109\/CVPRW.2011.5981788"},{"key":"17_CR29","doi-asserted-by":"crossref","unstructured":"Richardson, E., et al.: Encoding in style: a stylegan encoder for image-to-image translation. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 2287\u20132296 (2021)","DOI":"10.1109\/CVPR46437.2021.00232"},{"key":"17_CR30","unstructured":"Rigaki, M., Garcia, S.: A survey of privacy attacks in machine learning. arXiv preprint arXiv:2007.07646 (2020)"},{"key":"17_CR31","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., Shmatikov, V.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), pp. 3\u201318. IEEE (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"17_CR32","unstructured":"Simonyan, K., Zisserman, A.: Very deep convolutional networks for large-scale image recognition. In: ICLR (2015)"},{"key":"17_CR33","unstructured":"Struppek, L., Hintersdorf, D., Correia, A.D.A., Adler, A., Kersting, K.: Plug & play attacks: towards robust and flexible model inversion attacks. In: ICML. Proceedings of Machine Learning Research, vol.\u00a0162, pp. 20522\u201320545. PMLR (2022)"},{"issue":"4","key":"17_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3450626.3459838","volume":"40","author":"O Tov","year":"2021","unstructured":"Tov, O., Alaluf, Y., Nitzan, Y., Patashnik, O., Cohen-Or, D.: Designing an encoder for stylegan image manipulation. ACM Trans. Graph. (TOG) 40(4), 1\u201314 (2021)","journal-title":"ACM Trans. Graph. (TOG)"},{"key":"17_CR35","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M.K., Ristenpart, T.: Stealing machine learning models via prediction $$\\{$$APIs$$\\}$$. In: 25th USENIX security symposium (USENIX Security 2016), pp. 601\u2013618 (2016)"},{"key":"17_CR36","first-page":"9706","volume":"34","author":"KC Wang","year":"2021","unstructured":"Wang, K.C., Fu, Y., Li, K., Khisti, A., Zemel, R., Makhzani, A.: Variational model inversion attacks. Adv. Neural. Inf. Process. Syst. 34, 9706\u20139719 (2021)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"17_CR37","doi-asserted-by":"crossref","unstructured":"Wang, T., Zhang, Y., Fan, Y., Wang, J., Chen, Q.: High-fidelity gan inversion for image attribute editing. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 11379\u201311388 (2022)","DOI":"10.1109\/CVPR52688.2022.01109"},{"issue":"3","key":"17_CR38","first-page":"3121","volume":"45","author":"W Xia","year":"2022","unstructured":"Xia, W., Zhang, Y., Yang, Y., Xue, J.H., Zhou, B., Yang, M.H.: Gan inversion: a survey. IEEE Trans. Pattern Anal. Mach. Intell. 45(3), 3121\u20133138 (2022)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"key":"17_CR39","doi-asserted-by":"crossref","unstructured":"Yang, Z., Zhang, J., Chang, E., Liang, Z.: Neural network inversion in adversarial setting via background knowledge alignment. In: CCS, pp. 225\u2013240. ACM (2019)","DOI":"10.1145\/3319535.3354261"},{"key":"17_CR40","doi-asserted-by":"publisher","unstructured":"Yao, X., Newson, A., Gousseau, Y., Hellier, P.: A style-based gan encoder for high fidelity reconstruction of images and videos. In: European Conference on Computer Vision, pp. 581\u2013597. Springer (2022). https:\/\/doi.org\/10.1007\/978-3-031-19784-0_34","DOI":"10.1007\/978-3-031-19784-0_34"},{"key":"17_CR41","unstructured":"Ye, D., Chen, H., Zhou, S., Zhu, T., Zhou, W., Ji, S.: Model inversion attack against transfer learning: Inverting a model without accessing it. arXiv preprint arXiv:2203.06570 (2022)"},{"key":"17_CR42","doi-asserted-by":"crossref","unstructured":"Ye, Z., Luo, W., Naseem, M.L., Yang, X., Shi, Y., Jia, Y.: C2fmi: corse-to-fine black-box model inversion attack. IEEE Trans. Dependable Sec. Comput. (2023)","DOI":"10.1109\/TDSC.2023.3285071"},{"key":"17_CR43","doi-asserted-by":"crossref","unstructured":"Yuan, X., Chen, K., Zhang, J., Zhang, W., Yu, N., Zhang, Y.: Pseudo label-guided model inversion attack via conditional generative adversarial network. arXiv preprint arXiv:2302.09814 (2023)","DOI":"10.1609\/aaai.v37i3.25442"},{"key":"17_CR44","doi-asserted-by":"crossref","unstructured":"Yuan, Z., Wu, F., Long, Y., Xiao, C., Li, B.: Secretgen: Privacy recovery on pre-trained models via distribution discrimination. In: European Conference on Computer Vision. pp. 139\u2013155. Springer (2022)","DOI":"10.1007\/978-3-031-20065-6_9"},{"key":"17_CR45","doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: CVPR, pp. 586\u2013595. Computer Vision Foundation \/ IEEE Computer Society (2018)","DOI":"10.1109\/CVPR.2018.00068"},{"key":"17_CR46","doi-asserted-by":"crossref","unstructured":"Zhang, Y., Jia, R., Pei, H., Wang, W., Li, B., Song, D.: The secret revealer: generative model-inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 253\u2013261 (2020)","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"17_CR47","doi-asserted-by":"publisher","unstructured":"Zhu, J., Shen, Y., Zhao, D., Zhou, B.: In-domain gan inversion for real image editing. In: European conference on computer vision. pp. 592\u2013608. Springer (2020). https:\/\/doi.org\/10.1007\/978-3-031-20065-6_9","DOI":"10.1007\/978-3-031-20065-6_9"},{"key":"17_CR48","doi-asserted-by":"publisher","first-page":"991","DOI":"10.1109\/TIFS.2022.3233190","volume":"18","author":"T Zhu","year":"2022","unstructured":"Zhu, T., Ye, D., Zhou, S., Liu, B., Zhou, W.: Label-only model inversion attacks: attack with the least information. IEEE Trans. Inf. Forensics Secur. 18, 991\u20131005 (2022)","journal-title":"IEEE Trans. Inf. Forensics Secur."}],"container-title":["Lecture Notes in Computer Science","Computer Vision \u2013 ECCV 2024"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-72764-1_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,11,30]],"date-time":"2024-11-30T06:28:39Z","timestamp":1732948119000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-72764-1_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10,25]]},"ISBN":["9783031727634","9783031727641"],"references-count":48,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-72764-1_17","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10,25]]},"assertion":[{"value":"25 October 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ECCV","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Conference on Computer Vision","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Milan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Italy","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"eccv2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/eccv2024.ecva.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}