Measuring Data Reconstruction Defenses in Collaborative Inference Systems
Mengda Yang, Ziang Li, Juan Wang, Hongxin Hu, Ao Ren, Xiaoyang Xu, Wenzhe Yi
摘要
The collaborative inference systems are designed to speed up the prediction processes in edge-cloud scenarios, where the local devices and the cloud system work together to run a complex deep-learning model. However, those edge-cloud collaborative inference systems are vulnerable to emerging reconstruction attacks, where malicious cloud service providers are able to recover the edge-side users' private data. To defend against such attacks, several defense countermeasures have been recently introduced. Unfortunately, little is known about the robustness of those defense countermeasures. In this paper, we take the first step towards measuring the robustness of those state-of-the-art defenses with respect to reconstruction attacks. Specifically, we show that the latent privacy features are still retained in the obfuscated representations. Motivated by such an observation, we design a technology called Sensitive Feature Distillation (SFD) to restore sensitive information from the protected feature representations. Our experiments show that SFD can break through defense mechanisms in model partitioning scenarios, demonstrating the inadequacy of existing defense mechanisms as a privacy-preserving technique against reconstruction attacks. We hope our findings inspire further work in improving the robustness of defense mechanisms against reconstruction attacks for collaborative inference systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- GAN You See Me? Enhanced Data Reconstruction Attacks against Split InferenceZiang Li, Mengda Yang, Yaxin Liu, Juan Wang 等NeurIPS 2023 · 被引用 29 次
- Posthoc privacy guarantees for collaborative inference with modified Propose-Test-ReleaseAbhishek Singh, Praneeth Vepakomma, Vivek Sharma, Ramesh RaskarNeurIPS 2023 · 被引用 16 次
- A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningXiaoyang Xu, Mengda Yang, Wenzhe Yi, Ziang Li 等CVPR 2024 · 被引用 13 次
- Reimagining Mutual Information for Enhanced Defense against Data Leakage in Collaborative InferenceLin Duan, Jingwei Sun, Jinyuan Jia, Yiran Chen 等NeurIPS 2024 · 被引用 5 次
- From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed LearningZiang Li, Hongguang Zhang, Juan Wang, Meihui Chen 等CVPR 2025
它引用的顶会 Paper18
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 被引用 5,137 次
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 被引用 1,581 次
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning ModelsAhmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang 等NDSS 2019 · 被引用 1,141 次
- Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant RepresentationsKaran Ganju, Qi Wang, Wei Yang, Carl A. Gunter 等CCS 2018 · 被引用 574 次
- Systematic Evaluation of Privacy Risks of Machine Learning ModelsLiwei Song, Prateek MittalUSENIX Security 2021 · 被引用 483 次
相关 Paper
- Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference SystemsSong Xia, Yi Yu, Wenhan Yang, Meiwen Ding 等CVPR 2025
- InfoDecom: Decomposing Information for Defending Against Privacy Leakage in Split InferenceRuijun Deng, Zhihui Lu, Qiang DuanAAAI 2026
- Privacy-Preserving Collaborative Learning With Automatic Transformation SearchWei Gao, Shangwei Guo, Tianwei Zhang, Han Qiu 等CVPR 2021
- Crafter: Facial Feature Crafting against Inversion-based Identity Theft on Deep ModelsShiming Wang, Zhe Ji, Liyao Xiang, Hao Zhang 等NDSS 2024
- CoPur: Certifiably Robust Collaborative Inference via Feature PurificationJing Liu, Chulin Xie, Sanmi Koyejo, Bo LiNeurIPS 2022 · 被引用 10 次
