Review of Research on Black-Box Model Inversion Attack
Shifei HE , Chen WANG , Xin LUO , Guangwei XU
Journal of Donghua University(English Edition) ›› 2026, Vol. 43 ›› Issue (4) : 49 -58.
The development of artificial intelligence has given rise to the paradigm of machine learning as a service, enabling users to either train the requisite models or employ pre-existing models to make predictions based on the training data that users provide. Despite various measures taken to prevent privacy leakage in machine learning, such as data deletion and anonymization, model inversion attack (MIA) remains capable of inferring sensitive information from user data to a certain extent. This paper reviews the current state of research on black-box MIA, with a particular focus on confidence-based MIA and label-based MIA. It further analyzes the MIA methodologies applied to the emerging modes such as text and audio in recent years, filling the gap in the current review of such modes. Finally, the paper discusses the future challenges and research directions for black-box MIA.
machine learning / model inversion attack / black-box model / privacy protection
| [1] |
|
| [2] |
|
| [3] |
|
| [4] |
|
| [5] |
|
| [6] |
|
| [7] |
|
| [8] |
|
| [9] |
|
| [10] |
|
| [11] |
|
| [12] |
|
| [13] |
|
| [14] |
|
| [15] |
|
| [16] |
|
| [17] |
|
| [18] |
|
| [19] |
|
| [20] |
|
| [21] |
|
| [22] |
|
| [23] |
|
| [24] |
|
| [25] |
|
| [26] |
|
| [27] |
|
| [28] |
|
| [29] |
|
| [30] |
|
| [31] |
|
| [32] |
|
| [33] |
|
| [34] |
|
| [35] |
|
| [36] |
|
| [37] |
|
| [38] |
|
| [39] |
|
| [40] |
|
| [41] |
|
| [42] |
|
| [43] |
|
| [44] |
|
| [45] |
|
| [46] |
|
| [47] |
|
| [48] |
|
| [49] |
|
| [50] |
|
| [51] |
|
| [52] |
|
| [53] |
|
| [54] |
|
| [55] |
|
| [56] |
|
| [57] |
|
| [58] |
|
| [59] |
|
| [60] |
|
| [61] |
|
/
| 〈 |
|
〉 |