What Is Model Inversion?

Model inversion is an attack technique where an adversary analyzes an AI model’s outputs to reconstruct or infer sensitive information from the data it was trained on.

Why It Matters

Even without direct access to a model’s training data, a sufficiently determined attacker can sometimes reverse-engineer sensitive details, personal information, proprietary data, by carefully studying how the model responds to different inputs.

A Practical Example

A researcher demonstrates that a facial recognition model can be queried repeatedly in ways that reconstruct an approximate image of a face that was part of its original training set, without ever having direct access to that training data.

Related Terms

Need help governing AI risk like this across your organization?

Cyberix’s AI Security & Governance service finds, governs, and secures the AI already in use inside your organization.

See AI Security & Governance →