arXiv:2506.19886cs.CRcs.IT2025-06被引 4

用扩散模型提升语义通信隐私,防攻击者完成下游任务

Diffusion-aided Task-oriented Semantic Communications with Model Inversion Attack

  • 在发送端加自噪声,动态调节语义信息并抗信道干扰
  • 接收端用扩散U-Net提升任务准确率,可选标签嵌入增强性能
  • 以攻击者任务准确率为评估标准,更真实反映隐私泄露风险

语义通信通过传输语义信息而非原始符号序列来提升传输效率。任务导向的语义通信仅保留与任务相关的信息,实现更大带宽节省。然而,基于神经网络的通信系统易受模型逆向攻击,攻击者可通过窃听传输数据推断敏感输入信息。传统研究假设攻击者试图完全重建原始输入,但实际中即使像素级指标(如PSNR、SSIM)较低,攻击者输出仍可能完成下游任务,表明存在敏感信息泄漏。因此,本文采用攻击者任务准确率作为更合适的攻击评估指标。为缩小合法接收方与攻击者之间的准确率差距,提出DiffSem——一种基于扩散模型的任务导向语义通信框架。该框架在发送端引入自噪声机制,自适应调节语义内容并补偿信道噪声;在接收端采用扩散U-Net结构,提升任务性能,且可选地通过自参考标签嵌入进一步强化。实验表明,合法接收方在任务准确率上显著优于攻击者,验证了所提框架的优越性。

原文摘要 · Abstract (English)

Semantic communication enhances transmission efficiency by conveying semantic information rather than raw input symbol sequences. Task-oriented semantic communication is a variant that tries to retains only task-specific information, thus achieving greater bandwidth savings. However, these neural-based communication systems are vulnerable to model inversion attacks, where adversaries try to infer sensitive input information from eavesdropped transmitted data. The key challenge, therefore, lies in preserving privacy while ensuring transmission correctness and robustness. While prior studies typically assume that adversaries aim to fully reconstruct the raw input in task-oriented settings, there exist scenarios where pixel-level metrics such as PSNR or SSIM are low, yet the adversary's outputs still suffice to accomplish the downstream task, indicating leakage of sensitive information. We therefore adopt the attacker's task accuracy as a more appropriate metric for evaluating attack effectiveness. To optimize the gap between the legitimate receiver's accuracy and the adversary's accuracy, we propose DiffSem, a diffusion-aided framework for task-oriented semantic communication. DiffSem integrates a transmitter-side self-noising mechanism that adaptively regulates semantic content while compensating for channel noise, and a receiver-side diffusion U-Net that enhances task performance and can be optionally strengthened by self-referential label embeddings. Our experiments demonstrate that DiffSem enables the legitimate receiver to achieve higher accuracy, thereby validating the superior performance of the proposed framework.

语义通信扩散模型隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。