Pith. sign in

REVIEW 1 cited by

SIDE: Surrogate Conditional Data Extraction from Diffusion Models

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2410.02467 v7 pith:NFIXUZEJ submitted 2024-10-03 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords datamodelsconditionalextractionsurrogatedpmssideattacks
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

As diffusion probabilistic models (DPMs) become central to Generative AI (GenAI), understanding their memorization behavior is essential for evaluating risks such as data leakage, copyright infringement, and trustworthiness. While prior research finds conditional DPMs highly susceptible to data extraction attacks using explicit prompts, unconditional models are often assumed to be safe. We challenge this view by introducing \textbf{Surrogate condItional Data Extraction (SIDE)}, a general framework that constructs data-driven surrogate conditions to enable targeted extraction from any DPM. Through extensive experiments on CIFAR-10, CelebA, ImageNet, and LAION-5B, we show that SIDE can successfully extract training data from so-called safe unconditional models, outperforming baseline attacks even on conditional models. Complementing these findings, we present a unified theoretical framework based on informative labels, demonstrating that all forms of conditioning, explicit or surrogate, amplify memorization. Our work redefines the threat landscape for DPMs, establishing precise conditioning as a fundamental vulnerability and setting a new, stronger benchmark for model privacy evaluation.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Memorization and Regularization in Generative Diffusion Models

    cs.LG 2025-01 conditional novelty 7.0 of 10

    The exact minimizer of the empirical score-matching loss makes reverse diffusion trajectories converge to training samples, and certain regularizers prevent that collapse.

Pith tools