Lune

DAC2025Top-tier venue

Ensembler: Protect Collaborative Inference Privacy from Model Inversion Attack via Selective Ensemble

Dancheng Liu, Chenhui Xu, Jiajie Li, Amir Nassereldine, Jinjun Xiong

2025Year

Abstract

For collaborative inference through a cloud computing platform, it is sometimes essential for the client to shield its sensitive information from the cloud provider. In this paper, we introduce Ensembler, an extensible framework designed to substantially increase the difficulty of conducting model inversion attacks by adversarial parties. Ensembler leverages selective model ensemble on the adversarial server to obfuscate the reconstruction of the client’s private information. Our experiments demonstrate that Ensembler can effectively shield input images from reconstruction attacks, even when the client only retains one layer of the network locally. Ensembler significantly outperforms baseline methods by up to 43.5%\mathbf{4 3. 5 \%} in structural similarity while only incurring 4.8% time overhead during inference.

Ask about this paper

Your agent reads all of it.

Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.

Questions to start from

Your agent calls

Luneget_paper_fulltext

Ask in Lune

Free to start. No credit card required.

lune papers fulltext a9a01a47-ddd3-4467-8e50-8461a631e89e

Builds on10

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines