{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,25]],"date-time":"2026-08-25T21:18:05Z","timestamp":1787692685785,"version":"build-2784847793"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","funder":[{"name":"National Science Foundation for Distinguished Young Scholars of China","award":["62425201"],"award-info":[{"award-number":["62425201"]}]},{"name":"National Natural Science Foundation of China","award":["62571298"],"award-info":[{"award-number":["62571298"]}]},{"name":"National Natural Science Foundation of China","award":["62576122"],"award-info":[{"award-number":["62576122"]}]},{"name":"National Natural Science Foundation of China","award":["62301189"],"award-info":[{"award-number":["62301189"]}]},{"name":"Shenzhen Science and Technology Program","award":["KJZD20240903103702004"],"award-info":[{"award-number":["KJZD20240903103702004"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,8,9]]},"DOI":"10.1145\/3770854.3780328","type":"proceedings-article","created":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T12:07:40Z","timestamp":1785499660000},"page":"1833-1843","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature Filtering"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-8525-1565","authenticated-orcid":false,"given":"Hongyao","family":"Yu","sequence":"first","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-3444-5807","authenticated-orcid":false,"given":"Yixiang","family":"Qiu","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0271-6579","authenticated-orcid":false,"given":"Hao","family":"Fang","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-8730-1878","authenticated-orcid":false,"given":"Tianqu","family":"Zhuang","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4798-230X","authenticated-orcid":false,"given":"Bin","family":"Chen","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology, Shenzhen, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-2352-4733","authenticated-orcid":false,"given":"Sijin","family":"Yu","sequence":"additional","affiliation":[{"name":"South China University of Technology, Guangzhou, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9725-5305","authenticated-orcid":false,"given":"Bin","family":"Wang","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8639-982X","authenticated-orcid":false,"given":"Shu-Tao","family":"Xia","sequence":"additional","affiliation":[{"name":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2587-8517","authenticated-orcid":false,"given":"Ke","family":"Xu","sequence":"additional","affiliation":[{"name":"Department of Computer Science and Technology, Tsinghua University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,20]]},"reference":[{"key":"e_1_3_2_2_1_1","volume-title":"Mirror: Model inversion for deep learning network with high fidelity. In NDSS.","author":"An Shengwei","year":"2022","unstructured":"Shengwei An, Guanhong Tao, Qiuling Xu, Yingqi Liu, Guangyu Shen, Yuan Yao, Jingwei Xu, and Xiangyu Zhang. 2022. Mirror: Model inversion for deep learning network with high fidelity. In NDSS."},{"key":"e_1_3_2_2_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/FG.2018.00020"},{"key":"e_1_3_2_2_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01587"},{"key":"e_1_3_2_2_4_1","first-page":"1924","article-title":"Know you at one glance: A compact vector representation for low-shot learning","author":"Cheng Yu","year":"2017","unstructured":"Yu Cheng, Jian Zhao, Zhecan Wang, Yan Xu, Karlekar Jayashree, Shengmei Shen, and Jiashi Feng. 2017. Know you at one glance: A compact vector representation for low-shot learning. In ICCVW. 1924-1932.","journal-title":"ICCVW."},{"key":"e_1_3_2_2_5_1","volume-title":"International conference on machine learning. PMLR, 854-863","author":"Cisse Moustapha","year":"2017","unstructured":"Moustapha Cisse, Piotr Bojanowski, Edouard Grave, Yann Dauphin, and Nicolas Usunier. 2017. Parseval networks: Improving robustness to adversarial examples. In International conference on machine learning. PMLR, 854-863."},{"key":"e_1_3_2_2_6_1","volume-title":"Unsupervised cross-lingual representation learning for speech recognition. arXiv preprint arXiv:2006.13979","author":"Conneau Alexis","year":"2020","unstructured":"Alexis Conneau, Alexei Baevski, Ronan Collobert, Abdelrahman Mohamed, and Michael Auli. 2020. Unsupervised cross-lingual representation learning for speech recognition. arXiv preprint arXiv:2006.13979 (2020)."},{"key":"e_1_3_2_2_7_1","unstructured":"Alexey Dosovitskiy Lucas Beyer Alexander Kolesnikov Dirk Weissenborn Xiaohua Zhai Thomas Unterthiner Mostafa Dehghani Matthias Minderer Georg Heigold Sylvain Gelly et al. 2020. An image is worth 16x16 words: Transformers for image recognition at scale. arXiv preprint arXiv:2010.11929 (2020)."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00458"},{"key":"e_1_3_2_2_9_1","volume-title":"Privacy Leakage on DNNs: A Survey of Model Inversion Attacks and Defenses. arXiv preprint arXiv:2402.04013","author":"Fang Hao","year":"2024","unstructured":"Hao Fang, Yixiang Qiu, Hongyao Yu, Wenbo Yu, Jiawei Kong, Baoli Chong, Bin Chen, Xuan Wang, and Shu-Tao Xia. 2024. Privacy Leakage on DNNs: A Survey of Model Inversion Attacks and Defenses. arXiv preprint arXiv:2402.04013 (2024)."},{"key":"e_1_3_2_2_10_1","volume-title":"Retrievals can be detrimental: A contrastive backdoor attack paradigm on retrieval-augmented diffusion models. arXiv preprint arXiv:2501.13340","author":"Fang Hao","year":"2025","unstructured":"Hao Fang, Xiaohang Sui, Hongyao Yu, Kuofeng Gao, Jiawei Kong, Sijin Yu, Bin Chen, Hao Wu, and Shu-Tao Xia. 2025. Retrievals can be detrimental: A contrastive backdoor attack paradigm on retrieval-augmented diffusion models. arXiv preprint arXiv:2501.13340 (2025)."},{"key":"e_1_3_2_2_11_1","volume-title":"Proceedings of the fourteenth international conference on artificial intelligence and statistics. JMLR Workshop and Conference Proceedings, 315-323","author":"Glorot Xavier","year":"2011","unstructured":"Xavier Glorot, Antoine Bordes, and Yoshua Bengio. 2011. Deep sparse rectifier neural networks. In Proceedings of the fourteenth international conference on artificial intelligence and statistics. JMLR Workshop and Conference Proceedings, 315-323."},{"key":"e_1_3_2_2_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_2_13_1","volume-title":"Keshigeyan Chandrasegaran, Ngoc-Bao Nguyen, and Ngai-Man Cheung.","author":"Ho Sy-Tuyen","year":"2024","unstructured":"Sy-Tuyen Ho, Koh Jun Hao, Keshigeyan Chandrasegaran, Ngoc-Bao Nguyen, and Ngai-Man Cheung. 2024. Model Inversion Robustness: Can Transfer Learning Help? arXiv preprint arXiv:2405.05588 (2024)."},{"key":"e_1_3_2_2_14_1","volume-title":"GaussTrap: Stealthy Poisoning Attacks on 3D Gaussian Splatting for Targeted Scene Confusion. arXiv preprint arXiv:2504.20829","author":"Hong Jiaxin","year":"2025","unstructured":"Jiaxin Hong, Sixu Chen, Shuoyang Sun, Hongyao Yu, Hao Fang, Yuqi Tan, Bin Chen, Shuhan Qi, and Jiawei Li. 2025. GaussTrap: Stealthy Poisoning Attacks on 3D Gaussian Splatting for Targeted Scene Confusion. arXiv preprint arXiv:2504.20829 (2025)."},{"key":"e_1_3_2_2_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"e_1_3_2_2_16_1","doi-asserted-by":"crossref","unstructured":"Jun Hao Koh Sy-Tuyen Ho Ngoc-Bao Nguyen and Ngai-man Cheung. 2024. On the Vulnerability of Skip Connections to Model Inversion Attacks. In ECCV.","DOI":"10.1007\/978-3-031-73004-7_9"},{"key":"e_1_3_2_2_17_1","first-page":"88486","article-title":"Trap-mid: Trapdoor-based defense against model inversion attacks","volume":"37","author":"Liu ZhenTing","year":"2024","unstructured":"ZhenTing Liu and ShangTse Chen. 2024. Trap-mid: Trapdoor-based defense against model inversion attacks. Advances in Neural Information Processing Systems, Vol. 37 (2024), 88486-88526.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01170"},{"key":"e_1_3_2_2_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"e_1_3_2_2_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2014.7025068"},{"key":"e_1_3_2_2_21_1","first-page":"16384","article-title":"Re-thinking Model Inversion Attacks Against Deep Neural Networks","author":"Nguyen Ngoc-Bao","year":"2023","unstructured":"Ngoc-Bao Nguyen, Keshigeyan Chandrasegaran, Milad Abdollahzadeh, and Ngai-Man Cheung. 2023. Re-thinking Model Inversion Attacks Against Deep Neural Networks. In CVPR. 16384-16393.","journal-title":"CVPR."},{"key":"e_1_3_2_2_22_1","first-page":"33338","article-title":"Pseudo-Private Data Guided Model Inversion Attacks","volume":"37","author":"Peng Xiong","year":"2025","unstructured":"Xiong Peng, Bo Han, Feng Liu, Tongliang Liu, and Mingyuan Zhou. 2025. Pseudo-Private Data Guided Model Inversion Attacks. Advances in Neural Information Processing Systems, Vol. 37 (2025), 33338-33375.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_2_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539376"},{"key":"e_1_3_2_2_24_1","unstructured":"Yixiang Qiu Hao Fang Hongyao Yu Bin Chen MeiKang Qiu and Shu-Tao Xia. 2024a. A Closer Look at GAN Priors: Exploiting Intermediate Features for Enhanced Model Inversion Attacks. In ECCV."},{"key":"e_1_3_2_2_25_1","volume-title":"Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization. arXiv preprint arXiv:2508.20613","author":"Qiu Yixiang","year":"2025","unstructured":"Yixiang Qiu, Yanhan Liu, Hongyao Yu, Hao Fang, Bin Chen, Shu-Tao Xia, and Ke Xu. 2025. Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization. arXiv preprint arXiv:2508.20613 (2025)."},{"key":"e_1_3_2_2_26_1","volume-title":"MIBench: A Comprehensive Benchmark for Model Inversion Attack and Defense. arXiv preprint arXiv:2410.05159","author":"Qiu Yixiang","year":"2024","unstructured":"Yixiang Qiu, Hongyao Yu, Hao Fang, Wenbo Yu, Bin Chen, Xuan Wang, Shu-Tao Xia, and Ke Xu. 2024b. MIBench: A Comprehensive Benchmark for Model Inversion Attack and Defense. arXiv preprint arXiv:2410.05159 (2024)."},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.01913"},{"key":"e_1_3_2_2_29_1","volume-title":"Antonia Adler, and Kristian Kersting.","author":"Struppek Lukas","year":"2022","unstructured":"Lukas Struppek, Dominik Hintersdorf, Antonio De Almeida Correira, Antonia Adler, and Kristian Kersting. 2022. Plug & Play Attacks: Towards Robust and Flexible Model Inversion Attacks. In ICML."},{"key":"e_1_3_2_2_30_1","volume-title":"The Twelfth International Conference on Learning Representations (ICLR).","author":"Struppek Lukas","year":"2024","unstructured":"Lukas Struppek, Dominik Hintersdorf, and Kristian Kersting. 2024. Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion Attacks. In The Twelfth International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_2_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-20053-3_27"},{"key":"e_1_3_2_2_32_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i13.17387"},{"key":"e_1_3_2_2_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3746027.3754700"},{"key":"e_1_3_2_2_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW69036.2025.00650"},{"key":"e_1_3_2_2_35_1","doi-asserted-by":"crossref","unstructured":"Xiaojian Yuan Kejiang Chen Jie Zhang Weiming Zhang Nenghai Yu and Yang Zhang. 2023. Pseudo Label-Guided Model Inversion Attack via Conditional Generative Adversarial Network. In AAAI.","DOI":"10.1609\/aaai.v37i3.25442"},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"crossref","unstructured":"Yuheng Zhang Ruoxi Jia Hengzhi Pei Wenxiao Wang Bo Li and Dawn Song. 2020. The secret revealer: Generative model-inversion attacks against deep neural networks. In CVPR.","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"e_1_3_2_2_37_1","volume-title":"International Conference on Learning Representations (ICLR).","author":"Zhuang Tianqu","year":"2025","unstructured":"Tianqu Zhuang, Hongyao Yu, Yixiang Qiu, Hao Fang, Bin Chen, and Shu-Tao Xia. 2025. Stealthy Shield Defense: A Conditional Mutual Information-Based Approach against Black-Box Model Inversion Attacks. In International Conference on Learning Representations (ICLR)."}],"event":{"name":"KDD '26: The 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining","location":"Jeju Island Republic of Korea","sponsor":["SIGMOD ACM Special Interest Group on Management of Data","SIGKDD ACM Special Interest Group on Knowledge Discovery in Data"]},"container-title":["Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.1"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3770854.3780328","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,25]],"date-time":"2026-08-25T20:19:22Z","timestamp":1787689162000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3770854.3780328"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,20]]},"references-count":37,"alternative-id":["10.1145\/3770854.3780328","10.1145\/3770854"],"URL":"https:\/\/doi.org\/10.1145\/3770854.3780328","relation":{},"subject":[],"published":{"date-parts":[[2026,4,20]]},"assertion":[{"value":"2026-04-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}