---
title: "Model inversion"
description: "An attack that reconstructs features of training subjects, such as a face, from a model's outputs and confidence scores."
canonical: https://aigovernanceengineer.com/glossary/model-inversion
author: "Jorge García Aibar"
license: "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)"
doi: https://doi.org/10.5281/zenodo.22956197
version: "0.5.0"
updated: 2026-09-24
---

# Model inversion

An attack that reconstructs features of training subjects, such as a face, from a model's outputs and confidence scores [1]. It can turn a deployed model into a channel for disclosing personal data.

- Developed in: [ch. 19, AI-specific privacy breaches](https://aigovernanceengineer.com/bok/privacy-and-ai#ai-specific-privacy-breaches)
- Chapters: [ch. 19, Privacy & AI](https://aigovernanceengineer.com/bok/privacy-and-ai)
- Contrast with: [Membership inference](https://aigovernanceengineer.com/glossary/membership-inference)
- In the glossary chapter: https://aigovernanceengineer.com/bok/glossary#t-model-inversion

## Sources

[1] "Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures" (Fredrikson, Jha and Ristenpart; CCS 2015). ACM. 2015-10-12. https://doi.org/10.1145/2810103.2813677 (verified: primary)
