Table 5 Ablation study on three target models using the FFHQ and celeba dataset. ↑and ↓ respectively symbolize that higher and lower scores give better attack performance.

From: Enhanced model inversion via frequency disentanglement and latent space optimization

Target model

Method

FFHQ→CelebA

CelebA→CelebA

ACC@1↑

ACC@5↑

FID↓

KNN↓

ACC@1↑

ACC@5↑

FID↓

KNN↓

VGG16

Go+ Lo

0.89 ± 0.0007

0.97 ± 0.0002

26.77

1283.25

0.97 ± 0.0001

1. ± 0.0000

18.00

1119.35

Go+ Ln

0.90 ± 0.0005

0.97 ± 0.0002

24.72

1277.56

0.99 ± 0.0001

1. ± 0.0000

19.81

1116.21

Gn+ Lo

0.87 ± 0.0011

0.98 ± 0.0001

23.41

1282.02

0.99 ± 0.0002

1. ± 0.0000

17.33

1085.50

Gn+ Ln

0.89 ± 0.0007

0.98 ± 0.0002

22.06

1276.85

0.99 ± 0.0001

1. ± 0.0000

16.91

1089.49

IR152

Go+ Lo

0.96 ± 0.0005

1. ± 0.0001

26.02

1179.81

1. ± 0.0001

1. ± 0.0000

22.35

1028.72

Go+ Ln

0.98 ± 00.0001

1. ± 00.0000

25.69

1155.57

1. ± 0.0000

1. ± 0.0000

19.68

1026.22

Gn+ Lo

0.98 ± 0.0004

1. ± 0.0000

25.63

1154.04

1. ± 0.0001

1. ± 0.0000

18.29

994.78

Gn+ Ln

0.97 ± 0.0005

1. ± 0.0001

25.03

1153.56

1. ± 0.0000

1. ± 0.0000

18.72

1007.35

FaceNet64

Go+ Lo

0.95 ± 0.0005

0.99 ± 0.0001

26.47

1239.91

0.99 ± 0.0002

1. ± 0.0000

24.29

1112.76

Go+ Ln

0.96 ± 0.0005

0.99 ± 0.0001

26.09

1236.67

0.99 ± 0.0001

1. ± 0.0000

23.40

1104.87

Gn+ Lo

0.96 ± 0.0003

0.99 ± 0.0000

22.36

1235.70

1. ± 0.0001

1. ± 0.0000

19.62

1081.71

Gn+ Ln

0.96 ± 0.0003

1. ± 0.0000

23.06

1233.18

1. ± 0.0000

1. ± 0.0000

18.39

1094.78