Image Classification on CelebA (Private) FFHQ (Public)
93.52AccuracyNo Defense
Evaluation Results
| Method | Links | ||||
|---|---|---|---|---|---|
| No DefenseAttack Method=KEDMI, Target Model (T)=IR152, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=62.6/62.62024.05 | 93.52 | 70.27 | 89.33 | 1,285 | |
| No DefenseAttack Method=GMI, Target Model (T)=IR152, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=62.6/62.62024.05 | 93.52 | 24.27 | 45.67 | 1,617 | |
| No DefenseAttack Method=KEDMI, Target Model (T)=VGG16, Pre-trained Dataset (D_pretrain)=ImageNet1K, |theta_c|/|theta_T|=16.8/16.82024.05 | 89 | 55.6 | 84.67 | 1,407 | |
| No DefenseAttack Method=GMI, Target Model (T)=VGG16, Pre-trained Dataset (D_pretrain)=ImageNet1K, |theta_c|/|theta_T|=16.8/16.82024.05 | 89 | 13.6 | 32 | 1,725 | |
| No DefenseAttack Method=KEDMI, Target Model (T)=FaceNet64, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=35.4/35.42024.05 | 88.5 | 57.87 | 82 | 1,409 | |
| No DefenseAttack Method=GMI, Target Model (T)=FaceNet64, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=35.4/35.42024.05 | 88.5 | 13.13 | 30.33 | 1,746 | |
| TL-DMIAttack Method=KEDMI, Target Model (T)=IR152, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=17.8/62.62024.05 | 86.7 | 46.53 | 72.67 | 1,454 | |
| TL-DMIAttack Method=GMI, Target Model (T)=IR152, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=17.8/62.62024.05 | 86.7 | 6.13 | 15 | 1,877 | |
| TL-DMIAttack Method=GMI, Target Model (T)=FaceNet64, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=34.4/35.42024.05 | 83.61 | 2.6 | 8.67 | 2,009 | |
| TL-DMIAttack Method=KEDMI, Target Model (T)=VGG16, Pre-trained Dataset (D_pretrain)=ImageNet1K, |theta_c|/|theta_T|=13.9/16.82024.05 | 83.41 | 34.53 | 65.33 | 1,554 | |
| TL-DMIAttack Method=KEDMI, Target Model (T)=FaceNet64, Pre-trained Dataset (D_pretrain)=MS-CelebA-1M, |theta_c|/|theta_T|=34.4/35.42024.05 | 83.41 | 15.27 | 31 | 1,751 | |
| TL-DMIAttack Method=GMI, Target Model (T)=VGG16, Pre-trained Dataset (D_pretrain)=ImageNet1K, |theta_c|/|theta_T|=13.9/16.82024.05 | 83.41 | 4.27 | 12.33 | 1,919 |