cs.LGOct 6, 2026

Adaptive Model Inversion Attacks Generalize a Privacy-Robustness Tradeoff

Authors: Shailen Smith, Rasmus Torp, Adam Breuer

Organizations: Department of Computer Science, Dartmouth College · Department of Government, Dartmouth College

Abstract

In this paper, we show that standard evaluations of high-resolution Model Inversion Attacks (MIAs) significantly underestimate training-data privacy leakage. State-of-the-art privacy defenses, standard training techniques such as MixUp and Adversarial Training, and undefended models all leak training images at rates 1.16 to 6.59 times higher on FaceScrub under simple adaptive changes to the attack, with the largest increases among defenses reporting the strongest privacy. We further show that measured leakage depends on the feature basis of the external classifier used to evaluate reconstructions: for the same reconstructed images, an adversarially trained Inception evaluator identifies the targeted identity at different rates than the standard Inception evaluator. Our results suggest that standard MIA evaluation can mistake optimization and measurement failures for privacy. These underestimated leakage rates also concealed a broader relationship between privacy and adversarial robustness. Once we adapt the attack and vary the evaluator, reconstruction leakage closely tracks adversarial robustness across recent defenses and standard training regimes, suggesting that robustness provides an attack-agnostic proxy for reconstruction vulnerability that applies far more broadly than previously theorized. This raises an open question: can a practical defense reduce training-data reconstruction without paying a corresponding cost in adversarial robustness?

Figures & tables

Appendix figures & tables2 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Reducing information dependency does not cause training data privacy. Adversarially non-robust features do

    Jul 14, 2026Rasmus Torp, Shailen K. Smith, Adam BreuerPrivacyTraining Data

  2. On the Relationship between Model Quantization and Model Inversion Attacks

    Sep 30, 2026Rongke Liu, Youwen ZhuQuantizedInverse Problem

  3. VanillaBench: The Hidden Accuracy Cost of Adversarial Robustness

    Jul 14, 2026Niklas Bunzel