用生成对抗网络和渐进优化,从分割推理中重建敏感图像数据
Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization
- 分层生成器逐步优化中间特征,提升重建语义准确性
- 在高分辨率和跨模型场景下,重建质量显著优于已有攻击方法
- 适用于隐私评估、安全系统设计者,尤其关注边缘计算隐私风险
深度神经网络复杂度上升促使分割推理(Split Inference, SI)广泛应用,通过将计算任务分配给终端设备与云端,降低延迟并保护用户隐私。然而,近期的数据重建攻击(Data Reconstruction Attacks, DRAs)表明,SI过程中交换的中间特征可能被用于恢复敏感输入数据,带来严重隐私风险。现有攻击方法通常仅对浅层模型有效,且未能充分利用语义先验,导致重建质量差、泛化能力弱。本文提出一种基于生成对抗网络的新型攻击框架,结合渐进特征优化(Progressive Feature Optimization, PFO),将生成器分解为分层模块,逐步精炼中间表示以增强重建图像的语义保真度。为稳定优化过程并提升图像真实感,引入L1-ball约束。大量实验表明,本方法在高分辨率场景、分布外设置及深层复杂模型上均显著超越已有攻击,重建性能大幅领先。
原文摘要 · Abstract (English)
The growing complexity of Deep Neural Networks (DNNs) has led to the adoption of Split Inference (SI), a collaborative paradigm that partitions computation between edge devices and the cloud to reduce latency and protect user privacy. However, recent advances in Data Reconstruction Attacks (DRAs) reveal that intermediate features exchanged in SI can be exploited to recover sensitive input data, posing significant privacy risks. Existing DRAs are typically effective only on shallow models and fail to fully leverage semantic priors, limiting their reconstruction quality and generalizability across datasets and model architectures. In this paper, we propose a novel GAN-based DRA framework with Progressive Feature Optimization (PFO), which decomposes the generator into hierarchical blocks and incrementally refines intermediate representations to enhance the semantic fidelity of reconstructed images. To stabilize the optimization and improve image realism, we introduce an L1-ball constraint during reconstruction. Extensive experiments show that our method outperforms prior attacks by a large margin, especially in high-resolution scenarios, out-of-distribution settings, and against deeper and more complex DNNs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。