Ginver: Generative Model Inversion Attacks Against Collaborative Inference
Yupeng Yin, Xianglong Zhang, Huanle Zhang, Feng Li, Yue Yu, Xiuzhen Cheng, Pengfei Hu
Abstract
Deep Learning (DL) has been widely adopted in almost all domains, from threat recognition to medical diagnosis. Albeit its supreme model accuracy, DL imposes a heavy burden on devices as it incurs overwhelming system overhead to execute DL models, especially on Internet-of-Things (IoT) and edge devices. Collaborative inference is a promising approach to supporting DL models, by which the data owner (the victim) runs the first layers of the model on her local device and then a cloud provider (the adversary) runs the remaining layers of the model. Compared to offloading the entire model to the cloud, the collaborative inference approach is more data privacy-preserving as the owner's model input is not exposed to outsiders. However, we show in this paper that the adversary can restore the victim's model input by exploiting the output of the victim's local model. Our attack is dubbed Ginver 1 : Generative model inversion attacks against collaborative inference. Once trained, Ginver can infer the victim's unseen model inputs without remaking the inversion attack model and thus has the generative capability. We extensively evaluate Ginver under different settings (e.g., whitebox and black-box of the victim's local model) and applications (e.g., CIFAR10 and FaceScrub datasets). The experimental results show that Ginver recovers high-quality images from the victims. CCS CONCEPTS • Security and privacy → Privacy protections; • Networks → Network privacy and anonymity.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a897f859-8a7e-46e1-821f-973be5e2794dCited by top-tier papers5
- Split Adaptation for Pre-trained Vision TransformersLixu Wang, Bingqi Shang, Yi Li, Payal Mohapatra et al.CVPR 2025
- Prompt Inversion Attack Against Collaborative Inference of Large Language ModelsWenjie Qu, Yuguang Zhou, Yongji Wu, Tingsong Xiao et al.S&P 2025
- Passive Inference Attacks on Split Learning via Adversarial RegularizationXiaochen Zhu, Xinjian Luo, Yuncheng Wu, Yangfan Jiang et al.NDSS 2025
- Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference SystemsSong Xia, Yi Yu, Wenhan Yang, Meiwen Ding et al.CVPR 2025
- InfoDecom: Decomposing Information for Defending Against Privacy Leakage in Split InferenceRuijun Deng, Zhihui Lu, Qiang DuanAAAI 2026
Builds on13
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Membership Inference Attacks From First PrinciplesNicholas Carlini, Steve Chien, Milad Nasr, Shuang Song et al.S&P 2022 · 1,049 citations
- Label-Only Membership Inference AttacksChristopher A. Choquette-Choo, Florian Tramèr, Nicholas Carlini, Nicolas PapernotICML 2021 · 628 citations
- An End-to-End Transformer Model for 3D Object DetectionIshan Misra, Rohit Girdhar, Armand JoulinICCV 2021 · 602 citations
- MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial ExamplesJinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang et al.CCS 2019 · 464 citations
Related papers
- Measuring Data Reconstruction Defenses in Collaborative Inference SystemsMengda Yang, Ziang Li, Juan Wang, Hongxin Hu et al.NeurIPS 2022 · 18 citations
- The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural NetworksYuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang et al.CVPR 2020
- When Deep Learning Meets Steganography: Protecting Inference Privacy in the DarkQin Liu, Jiamin Yang, Hongbo Jiang, Jie Wu et al.INFOCOM 2022 · 8 citations
- Ensembler: Protect Collaborative Inference Privacy from Model Inversion Attack via Selective EnsembleDancheng Liu, Chenhui Xu, Jiajie Li, Amir Nassereldine et al.DAC 2025
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
