Lune

ICML2026顶会

Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference

Rongke Liu, Youwen Zhu, Lei Zhou, Zhang Xianglong, Dong Wang

2026年份

摘要

In collaborative inference (CI), transmitting intermediate representations ZZ from edge devices enables model inversion attacks (MIA) that reconstruct the original inputs XX, while existing defenses mainly perturb shallow-layer ZZ at the cost of utility. We instead ask: where should an edge–cloud model be partitioned to obtain intrinsic resistance to MIA? We challenge the intuition that depth is the driver of MIA resistance, and show that depth is sufficient only insofar as it enables a representational transition; this transition is necessary for intrinsic resistance and is marked by an abrupt rise in the lower bound of H(X∣Z)H(X|Z). Correspondingly, the decisive variance term in the entropy bound shifts from a global variance to the intra-class mean-squared radius Rc2R^2_c rather than dimensionality alone, yielding an Rc2R^2_c-based criterion to locate the transition zone, or identify it post hoc from MIA outcomes, which we term the Golden Partition Zone (GPZ). We further explain how Rc2R^2_c evolves during training and show that it can be controlled through the label distribution; we refer to this controllable dynamic behavior as the Neural Vortex, an analysis-backed explanatory concept. Across four representative deep vision models, partitioning at the GPZ yields over 4× higher reconstruction MSE compared to shallow splits; under entropy and inversion-model enhancements, decision-level representations provide 66% stronger resistance than feature-level ones, and we further observe that data type affects both the transition boundary and reconstruction.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

它引用的顶会 Paper5

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖