mirror

anonymous repo for showing more results

View on GitHub

ResNet50 pre-trained on VGGFACE2, label 61

Index: HOME / VGGFACE2 / ResNet50 / label 61

Red numbers denote the target confidence. For the white-box inversion, we run with a batch size of 8. For the black-box inversion, AMI only returns 1 image so we only generate 1 image.

Target Person

8 images of the target person with the largest file size from VGGFACE2

Target person

GMI (white-box)

GMI

PGGAN (white-box)

PGGAN

MIRROR (ours white-box)

MIRROR white-box

AMI (black-box)

AMI

MIRROR (ours black-box)

MIRROR black-box