Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference
Rongke Liu, Youwen Zhu, Lei Zhou, Zhang Xianglong, Dong Wang
摘要
In collaborative inference (CI), transmitting intermediate representations from edge devices enables model inversion attacks (MIA) that reconstruct the original inputs , while existing defenses mainly perturb shallow-layer at the cost of utility. We instead ask: where should an edge–cloud model be partitioned to obtain intrinsic resistance to MIA? We challenge the intuition that depth is the driver of MIA resistance, and show that depth is sufficient only insofar as it enables a representational transition; this transition is necessary for intrinsic resistance and is marked by an abrupt rise in the lower bound of . Correspondingly, the decisive variance term in the entropy bound shifts from a global variance to the intra-class mean-squared radius rather than dimensionality alone, yielding an -based criterion to locate the transition zone, or identify it post hoc from MIA outcomes, which we term the Golden Partition Zone (GPZ). We further explain how evolves during training and show that it can be controlled through the label distribution; we refer to this controllable dynamic behavior as the Neural Vortex, an analysis-backed explanatory concept. Across four representative deep vision models, partitioning at the GPZ yields over 4× higher reconstruction MSE compared to shallow splits; under entropy and inversion-model enhancements, decision-level representations provide 66% stronger resistance than feature-level ones, and we further observe that data type affects both the transition boundary and reconstruction.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper5
- Swin Transformer: Hierarchical Vision Transformer using Shifted WindowsZe Liu, Yutong Lin, Yue Cao, Han Hu 等ICCV 2021 · 被引用 31,683 次
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn 等ICLR 2021 · 被引用 21,477 次
- Improving Robustness to Model Inversion Attacks via Mutual Information RegularizationTianhao Wang, Yuheng Zhang, Ruoxi JiaAAAI 2021 · 被引用 98 次
- Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion AttacksLukas Struppek, Dominik Hintersdorf, Kristian KerstingICLR 2024 · 被引用 26 次
- Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference SystemsSong Xia, Yi Yu, Wenhan Yang, Meiwen Ding 等CVPR 2025
相关 Paper
- Measuring Data Reconstruction Defenses in Collaborative Inference SystemsMengda Yang, Ziang Li, Juan Wang, Hongxin Hu 等NeurIPS 2022 · 被引用 18 次
- Reimagining Mutual Information for Enhanced Defense against Data Leakage in Collaborative InferenceLin Duan, Jingwei Sun, Jinyuan Jia, Yiran Chen 等NeurIPS 2024 · 被引用 5 次
- Ginver: Generative Model Inversion Attacks Against Collaborative InferenceYupeng Yin, Xianglong Zhang, Huanle Zhang, Feng Li 等WWW 2023 · 被引用 24 次
- GAN You See Me? Enhanced Data Reconstruction Attacks against Split InferenceZiang Li, Mengda Yang, Yaxin Liu, Juan Wang 等NeurIPS 2023 · 被引用 29 次
- Bilateral Dependency Optimization: Defending Against Model-inversion AttacksXiong Peng, Feng Liu, Jingfeng Zhang, Long Lan 等KDD 2022 · 被引用 20 次
