arXiv:2510.23274cs.CReess.IV2025-10被引 2

用可学习的差分隐私噪声保护图像语义通信,兼顾安全与性能。

Privacy-Preserving Semantic Communication over Wiretap Channels with Learnable Differential Privacy

  • 通过生成对抗网络逆向提取语义特征,再注入可学习的差分隐私噪声
  • 在同等安全水平下,使窃听者重建质量显著下降,合法用户损失极小
  • 支持按需调节隐私预算,实现可控安全等级,适合实际部署

语义通信(SemCom)通过聚焦任务相关的信息提升了传输效率,但也带来了严重的隐私问题。现有安全语义通信方法多依赖于苛刻或不切实际的假设,如对合法用户有利的信道条件或对窃听者模型的先验知识。为此,本文提出一种针对无线窃听信道的新型安全语义通信框架,用于图像传输,利用差分隐私(DP)提供近似隐私保障。具体地,首先采用生成对抗网络(GAN)逆向方法从源图像中提取解耦的语义表示,随后对私有语义表示选择性地注入近似差分隐私噪声。不同于传统白高斯或拉普拉斯噪声,本方法通过神经网络对抗训练引入可学习的噪声模式,缓解了差分隐私固有的不可逆性问题,同时有效保护隐私信息。此外,可通过调整隐私预算显式控制安全级别,这是大多数现有安全语义通信方法所不具备的。实验结果表明,相比先前基于差分隐私的方法和直接传输,该方法显著降低了窃听者的重构质量,而合法用户的任务性能仅轻微下降。在相近安全水平下,本方法相较之前基于差分隐私的方法,在合法用户端实现了0.06–0.29的LPIPS优势和0.10–0.86的FPPSR优势。

原文摘要 · Abstract (English)

While semantic communication (SemCom) improves transmission efficiency by focusing on task-relevant information, it also raises critical privacy concerns. Many existing secure SemCom approaches rely on restrictive or impractical assumptions, such as favorable channel conditions for the legitimate user or prior knowledge of the eavesdropper's model. To address these limitations, this paper proposes a novel secure SemCom framework for image transmission over wiretap channels, leveraging differential privacy (DP) to provide approximate privacy guarantees. Specifically, our approach first extracts disentangled semantic representations from source images using generative adversarial network (GAN) inversion method, and then selectively perturbs private semantic representations with approximate DP noise. Distinct from conventional DP-based protection methods, we introduce DP noise with learnable pattern, instead of traditional white Gaussian or Laplace noise, achieved through adversarial training of neural networks (NNs). This design mitigates the inherent non-invertibility of DP while effectively protecting private information. Moreover, it enables explicitly controllable security levels by adjusting the privacy budget according to specific security requirements, which is not achieved in most existing secure SemCom approaches. Experimental results demonstrate that, compared with the previous DP-based method and direct transmission, the proposed method significantly degrades the reconstruction quality for the eavesdropper, while introducing only slight degradation in task performance. Under comparable security levels, our approach achieves an LPIPS advantage of 0.06-0.29 and an FPPSR advantage of 0.10-0.86 for the legitimate user compared with the previous DP-based method.

语义通信差分隐私图像传输安全通信

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。