The study presents Diff-MI, a two-stage attack designed for situations in which an attacker has full access to an AI classifier. It first trains a conditional image generator using public images and labels inferred from the classifier, then repeatedly reconstructs images using both the generator and information from the classifier.

Across datasets and model types, the method improved the visual fidelity of reconstructed images compared with existing approaches. The authors report an average 20% reduction in FID, a measure in which lower scores generally indicate that generated images are closer to real ones, while keeping competitive attack accuracy.