InstaHide's Sample Complexity When Mixing Two Private Images
- MIACV
Abstract
Inspired by InstaHide challenge [Huang, Song, Li and Arora'20], [Chen, Song and Zhuo'20] recently provides one mathematical formulation of InstaHide attack problem under Gaussian images distribution. They show that it suffices to use samples to recover one private image in time for any integer , where and denote the number of images used in the private and the public dataset to generate a mixed image sample. Under the current setup for the InstaHide challenge of mixing two private images (), this means samples are sufficient to recover a private image. In this work, we show that samples are sufficient (information-theoretically) for recovering all the private images.
View on arXivComments on this paper
