跳到主要內容區
       返回首頁 聯絡我們  管理介面  English中山大學

 

基於陷阱後門的模型逆向攻擊之防禦 Trapdoor-based Defense against Model Inversion Attacks

摘要 Abstract 

模型逆向攻擊能從AI模型重建訓練資料,對隱私構成重大威脅。本次演講將介紹 Trap-MID,一種將陷阱觸發器(trapdoor trigger)嵌入模型的防禦方法,藉此誤導攻擊者重建出陷阱圖樣,而非真實隱私資料。與傳統正則化式防禦不同,Trap-MID 透過欺敵策略來保護隱私。我將展示此方法在各類模型逆向攻擊下達到最先進防禦效果,且無需額外資料或大量運算資源。

Model Inversion (MI) attacks threaten data privacy by reconstructing training data from AI models. This talk presents Trap-MID, a defense that embeds a trapdoor trigger into the model, causing MI attacks to recover the trapdoor pattern instead of private data. Unlike traditional regularization-based defenses, Trap-MID uses deception to mislead attackers. I will discuss theoretical insights on trapdoor effectiveness and naturalness, along with empirical results showing state-of-the-art performance against various MI attacks—achieved without extra data or significant overhead.

poster

場次: 7
演講日期: 2025-04-25
主講人: 陳尚澤博士/國立台灣大學資訊工程學系暨研究所副教授
瀏覽數:
系主任給系友的一封信
新聞亮點
656456456
活動報導
畢業系友聯絡資料更新