mirror

anonymous repo for showing more results

View on GitHub

VGG16BN pre-trained on VGGFACE, label 1

Index: HOME / VGGFACE / VGG16BN / label 1

Red numbers denote the target confidence. For the white-box inversion, we run with a batch size of 8. For the black-box inversion, AMI only returns 1 image so we only generate 1 image.

Target Person

8 images of the target person with the largest file size from VGGFACE

Target person

GMI (white-box)

GMI

PGGAN (white-box)

PGGAN

MIRROR (ours white-box)

MIRROR white-box

AMI (black-box)

AMI

MIRROR (ours black-box)

MIRROR black-box