When Deep Learning Meets Steganography: Protecting Inference Privacy in the Dark
Qin Liu, Jiamin Yang, Hongbo Jiang, Jie Wu, Tao Peng, Tian Wang, Guojun Wang
Abstract
While cloud-based deep learning benefits for high-accuracy inference, it leads to potential privacy risks when exposing sensitive data to untrusted servers. In this paper, we work on exploring the feasibility of steganography in preserving inference privacy. Specifically, we devise GHOST and GHOST+, two private inference solutions employing steganography to make sensitive images invisible in the inference phase. Motivated by the fact that deep neural networks (DNNs) are inherently vulnerable to adversarial attacks, our main idea is turning this vulnerability into the weapon for data privacy, enabling the DNN to misclassify a stego image into the class of the sensitive image hidden in it. The main difference is that GHOST retrains the DNN into a poisoned network to learn the hidden features of sensitive images, but GHOST+ leverages a generative adversarial network (GAN) to produce adversarial perturbations without altering the DNN. For enhanced privacy and a better computation-communication trade-off, both solutions adopt the edge-cloud collaborative framework. Compared with the previous solutions, this is the first work that successfully integrates steganography and the nature of DNNs to achieve private inference while ensuring high accuracy. Extensive experiments validate that steganography has excellent ability in accuracy-aware privacy protection of deep learning.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get e48ae752-34fc-417f-bdd4-a44ad842fcbcRelated papers
- GAN You See Me? Enhanced Data Reconstruction Attacks against Split InferenceZiang Li, Mengda Yang, Yaxin Liu, Juan Wang et al.NeurIPS 2023 · 29 citations
- Ginver: Generative Model Inversion Attacks Against Collaborative InferenceYupeng Yin, Xianglong Zhang, Huanle Zhang, Feng Li et al.WWW 2023 · 24 citations
- Phantom: Privacy-Preserving Deep Neural Network Model Obfuscation in Heterogeneous TEE and GPU SystemJuyang Bai, Md Hafizul Islam Chowdhuryy, Jingtao Li, Fan Yao et al.USENIX Security 2025
- Crafter: Facial Feature Crafting against Inversion-based Identity Theft on Deep ModelsShiming Wang, Zhe Ji, Liyao Xiang, Hao Zhang et al.NDSS 2024
- Shredder: Learning Noise Distributions to Protect Inference PrivacyFatemehsadat Mireshghallah, Mohammadkazem Taram, Prakash Ramrakhyani, Ali Jalali et al.ASPLOS 2020 · 80 citations
