Pith. sign in

REVIEW 1 cited by

Does CLIP Know My Face?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2209.07341 v4 pith:HWDFTVF5 submitted 2022-09-15 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords privacytrainingmodelmodelsclipdatausedindividuals
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

With the rise of deep learning in various applications, privacy concerns around the protection of training data have become a critical area of research. Whereas prior studies have focused on privacy risks in single-modal models, we introduce a novel method to assess privacy for multi-modal models, specifically vision-language models like CLIP. The proposed Identity Inference Attack (IDIA) reveals whether an individual was included in the training data by querying the model with images of the same person. Letting the model choose from a wide variety of possible text labels, the model reveals whether it recognizes the person and, therefore, was used for training. Our large-scale experiments on CLIP demonstrate that individuals used for training can be identified with very high accuracy. We confirm that the model has learned to associate names with depicted individuals, implying the existence of sensitive information that can be extracted by adversaries. Our results highlight the need for stronger privacy protection in large-scale models and suggest that IDIAs can be used to prove the unauthorized use of data for training and to enforce privacy laws.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. The Cake that is Intelligence and Who Gets to Bake it: An AI Analogy and its Implications for Participation

    cs.AI 2025-02 accept novelty 5.0 of 10

    The authors expand LeCun's cake metaphor to the full AI lifecycle and argue that social outcomes are constrained by technical foundations such as the i.i.d. assumption, homogenization, catastrophic forgetting, and sur...

Pith tools