about
Reconstructing Training Data from Trained Neural Networks (arxiv.org)
1 point by groar on Jun 21, 2022 | hide | past | pdf | discuss on HN

In plain words: A trick that pulls real training images out of a trained network's weights, using the fact that gradient training settles on the simplest solution. It recovered a significant share of the actual images from simple image-sorting networks, so such models can leak private data.

Abstract

Understanding to what extent neural networks memorize training data is an intriguing question with practical and theoretical implications. In this paper we show that in some cases a significant fraction of the training data can in fact be reconstructed from the parameters of a trained neural network classifier. We propose a novel reconstruction scheme that stems from recent theoretical results about the implicit bias in training neural networks with gradient-based methods. To the best of our knowledge, our results are the first to show that reconstructing a large portion of the actual training samples from a trained neural network classifier is generally possible. This has negative implications on privacy, as it can be used as an attack for revealing sensitive training data. We demonstrate our method for binary MLP classifiers on a few standard computer vision datasets.

Niv Haim, Gal Vardi, Gilad Yehudai, Ohad Shamir, Michal Irani
arXiv:2206.07758 · cs.LG, cs.CR, cs.CV, cs.NE, stat.ML · submitted Jun 15, 2022 · updated Dec 5, 2022
abstract · pdf · html · Fixed a typo in the acknowledgements

add comment on HN