Table 5 Ablation study on three target models using the FFHQ and celeba dataset. ↑and ↓ respectively symbolize that higher and lower scores give better attack performance.
From: Enhanced model inversion via frequency disentanglement and latent space optimization
Target model | Method | FFHQ→CelebA | CelebA→CelebA | ||||||
|---|---|---|---|---|---|---|---|---|---|
ACC@1↑ | ACC@5↑ | FID↓ | KNN↓ | ACC@1↑ | ACC@5↑ | FID↓ | KNN↓ | ||
VGG16 | Go+ Lo | 0.89 ± 0.0007 | 0.97 ± 0.0002 | 26.77 | 1283.25 | 0.97 ± 0.0001 | 1. ± 0.0000 | 18.00 | 1119.35 |
Go+ Ln | 0.90 ± 0.0005 | 0.97 ± 0.0002 | 24.72 | 1277.56 | 0.99 ± 0.0001 | 1. ± 0.0000 | 19.81 | 1116.21 | |
Gn+ Lo | 0.87 ± 0.0011 | 0.98 ± 0.0001 | 23.41 | 1282.02 | 0.99 ± 0.0002 | 1. ± 0.0000 | 17.33 | 1085.50 | |
Gn+ Ln | 0.89 ± 0.0007 | 0.98 ± 0.0002 | 22.06 | 1276.85 | 0.99 ± 0.0001 | 1. ± 0.0000 | 16.91 | 1089.49 | |
IR152 | Go+ Lo | 0.96 ± 0.0005 | 1. ± 0.0001 | 26.02 | 1179.81 | 1. ± 0.0001 | 1. ± 0.0000 | 22.35 | 1028.72 |
Go+ Ln | 0.98 ± 00.0001 | 1. ± 00.0000 | 25.69 | 1155.57 | 1. ± 0.0000 | 1. ± 0.0000 | 19.68 | 1026.22 | |
Gn+ Lo | 0.98 ± 0.0004 | 1. ± 0.0000 | 25.63 | 1154.04 | 1. ± 0.0001 | 1. ± 0.0000 | 18.29 | 994.78 | |
Gn+ Ln | 0.97 ± 0.0005 | 1. ± 0.0001 | 25.03 | 1153.56 | 1. ± 0.0000 | 1. ± 0.0000 | 18.72 | 1007.35 | |
FaceNet64 | Go+ Lo | 0.95 ± 0.0005 | 0.99 ± 0.0001 | 26.47 | 1239.91 | 0.99 ± 0.0002 | 1. ± 0.0000 | 24.29 | 1112.76 |
Go+ Ln | 0.96 ± 0.0005 | 0.99 ± 0.0001 | 26.09 | 1236.67 | 0.99 ± 0.0001 | 1. ± 0.0000 | 23.40 | 1104.87 | |
Gn+ Lo | 0.96 ± 0.0003 | 0.99 ± 0.0000 | 22.36 | 1235.70 | 1. ± 0.0001 | 1. ± 0.0000 | 19.62 | 1081.71 | |
Gn+ Ln | 0.96 ± 0.0003 | 1. ± 0.0000 | 23.06 | 1233.18 | 1. ± 0.0000 | 1. ± 0.0000 | 18.39 | 1094.78 | |