Measuring Data Reconstruction Defenses in Collaborative Inference Systems
Mengda Yang, Ziang Li, Juan Wang, Hongxin Hu, Ao Ren, Xiaoyang Xu, Wenzhe Yi
Abstract
The collaborative inference systems are designed to speed up the prediction processes in edge-cloud scenarios, where the local devices and the cloud system work together to run a complex deep-learning model. However, those edge-cloud collaborative inference systems are vulnerable to emerging reconstruction attacks, where malicious cloud service providers are able to recover the edge-side users' private data. To defend against such attacks, several defense countermeasures have been recently introduced. Unfortunately, little is known about the robustness of those defense countermeasures. In this paper, we take the first step towards measuring the robustness of those state-of-the-art defenses with respect to reconstruction attacks. Specifically, we show that the latent privacy features are still retained in the obfuscated representations. Motivated by such an observation, we design a technology called Sensitive Feature Distillation (SFD) to restore sensitive information from the protected feature representations. Our experiments show that SFD can break through defense mechanisms in model partitioning scenarios, demonstrating the inadequacy of existing defense mechanisms as a privacy-preserving technique against reconstruction attacks. We hope our findings inspire further work in improving the robustness of defense mechanisms against reconstruction attacks for collaborative inference systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers7
- GAN You See Me? Enhanced Data Reconstruction Attacks against Split InferenceZiang Li, Mengda Yang, Yaxin Liu, Juan Wang et al.NeurIPS 2023 · 29 citations
- Posthoc privacy guarantees for collaborative inference with modified Propose-Test-ReleaseAbhishek Singh, Praneeth Vepakomma, Vivek Sharma, Ramesh RaskarNeurIPS 2023 · 16 citations
- A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningXiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li et al.CVPR 2024 · 13 citations
- Reimagining Mutual Information for Enhanced Defense against Data Leakage in Collaborative InferenceLin Duan, Jingwei Sun, Jinyuan Jia, Yiran Chen et al.NeurIPS 2024 · 5 citations
- From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed LearningZiang Li, Hongguang Zhang, Juan Wang, Meihui Chen et al.CVPR 2025
Builds on18
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang et al.NDSS 2019 · 1,141 citations
- Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant RepresentationsKaran Ganju, Qi Wang, Wei Yang, Carl A. Gunter et al.CCS 2018 · 574 citations
- Systematic Evaluation of Privacy Risks of Machine Learning ModelsLiwei Song, Prateek MittalUSENIX Security 2021 · 483 citations
Related papers
- Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference SystemsSong Xia, Yi Yu, Wenhan Yang, Meiwen Ding et al.CVPR 2025
- InfoDecom: Decomposing Information for Defending Against Privacy Leakage in Split InferenceRuijun Deng, Zhihui Lu, Qiang DuanAAAI 2026
- Privacy-Preserving Collaborative Learning With Automatic Transformation SearchWei Gao, Shangwei Guo, Tianwei Zhang, Han Qiu et al.CVPR 2021
- Crafter: Facial Feature Crafting against Inversion-based Identity Theft on Deep ModelsShiming Wang, Zhe Ji, Liyao Xiang, Hao Zhang et al.NDSS 2024
- CoPur: Certifiably Robust Collaborative Inference via Feature PurificationJing Liu, Chulin Xie, Sanmi Koyejo, Bo LiNeurIPS 2022 · 10 citations
