Pith. sign in

REVIEW 3 cited by

Reconstructing Training Data from Multiclass Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2305.03350 v1 pith:Y63YY22V submitted 2023-05-05 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords trainingneuralreconstructionsamplesworkbinaryclassesnetworks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Reconstructing samples from the training set of trained neural networks is a major privacy concern. Haim et al. (2022) recently showed that it is possible to reconstruct training samples from neural network binary classifiers, based on theoretical results about the implicit bias of gradient methods. In this work, we present several improvements and new insights over this previous work. As our main improvement, we show that training-data reconstruction is possible in the multi-class setting and that the reconstruction quality is even higher than in the case of binary classification. Moreover, we show that using weight-decay during training increases the vulnerability to sample reconstruction. Finally, while in the previous work the training set was of size at most $1000$ from $10$ classes, we show preliminary evidence of the ability to reconstruct from a model trained on $5000$ samples from $100$ classes.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Shortcut Learning Susceptibility in Vision Classifiers

    cs.LG 2025-02 reject novelty 5.0 of 10

    CNNs showed the most resistance to position and intensity shortcuts, ViTs with positional encodings relied on shortcuts most, and lower learning rates reduced shortcut reliance.

  2. Privacy Preserving Properties of Vision Classifiers

    cs.LG 2025-02 reject novelty 4.0 of 10

    Using a self-built network inversion generator, the authors report SSIM-based reconstruction quality rankings across MNIST, FashionMNIST, SVHN, and CIFAR-10, finding MLP greater than ViT greater than CNN in memorizati...

  3. Securing AI Systems: A Guide to Known Attacks and Impacts

    cs.CR 2025-06 conditional novelty 3.0 of 10

    A practitioner-oriented review that organizes known adversarial attacks on predictive and generative AI systems into eleven types mapped to confidentiality, integrity, and availability impacts.

Pith tools