What does 'model inversion attack' allow an adversary to do?
-
A
Flip the model's predictions to the opposite class
-
B
Reconstruct approximate training data from model outputs
-
C
Inject backdoors during fine-tuning
-
D
Replace a production model with a malicious replica