提出新方法评估视觉模型中间层隐私风险,无需攻击模拟。
Intermediate Outputs Are More Sensitive Than You Think
- 用自由度和雅可比矩阵秩衡量中间输出信息量与敏感度。
- 实验证明该方法能系统识别各层隐私风险,准确率高。
- 适合关注模型隐私安全的研究者与开发者使用。
深度视觉模型处理敏感数据时,隐藏层的中间输出可能暴露隐私。现有隐私评估多聚焦整体输出,忽视中间表示的漏洞。当前方法依赖特定攻击模拟,计算成本高且不完整。本文提出基于自由度(DoF)和中间输出敏感度的新评估框架,无需对抗攻击即可量化各层信息保留量与输入扰动响应。通过结合自由度分析与雅可比矩阵秩,实现对模型各层隐私风险的系统测量。在真实数据集上的实验验证了该方法的有效性,揭示了中间表示的深层隐私风险。
原文摘要 · Abstract (English)
The increasing reliance on deep computer vision models that process sensitive data has raised significant privacy concerns, particularly regarding the exposure of intermediate results in hidden layers. While traditional privacy risk assessment techniques focus on protecting overall model outputs, they often overlook vulnerabilities within these intermediate representations. Current privacy risk assessment techniques typically rely on specific attack simulations to assess risk, which can be computationally expensive and incomplete. This paper introduces a novel approach to measuring privacy risks in deep computer vision models based on the Degrees of Freedom (DoF) and sensitivity of intermediate outputs, without requiring adversarial attack simulations. We propose a framework that leverages DoF to evaluate the amount of information retained in each layer and combines this with the rank of the Jacobian matrix to assess sensitivity to input variations. This dual analysis enables systematic measurement of privacy risks at various model layers. Our experimental validation on real-world datasets demonstrates the effectiveness of this approach in providing deeper insights into privacy risks associated with intermediate representations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。