Model inversion

An attack that reconstructs features of training subjects, such as a face, from a model's outputs and confidence scores 1. It can turn a deployed model into a channel for disclosing personal data.

Developed in
ch. 19, AI-specific privacy breaches
Chapters
ch. 19, Privacy & AI
Contrast with
Membership inference
Source
1 numbered reference, listed below

Where it is used

One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.

Patterns that use this term

One pattern page uses the term.

Sources

  1. [1] "Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures" (Fredrikson, Jha and Ristenpart; CCS 2015). ACM. 2015-10-12. https://doi.org/10.1145/2810103.2813677 (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Model inversion. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/model-inversion. CC BY 4.0

BibTeX

@misc{aige2026modelinversion,
  author  = {Jorge García Aibar},
  title   = {{Model inversion}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/model-inversion}
}