arXiv:2511.15316cs.CV2025-11被引 2

通过特征逆向攻击,高保真还原分割式神经网络的隐私输入。

What Your Features Reveal: Data-Efficient Black-Box Feature Inversion Attack for Split DNNs

  • 设计语义对齐模块与确定性流匹配,提升中间特征重建质量。
  • 仅需少量图像-特征配对即可训练,实现黑盒高效逆向。
  • 基于视觉语言模型评估,揭示分割神经网络更严重隐私风险。

分割式神经网络通过将计算任务分发至云端,使边缘设备成为可能,但该范式暴露了隐私漏洞:中间特征可被用于重构私有输入。现有特征逆向攻击方法重建质量有限,难以准确评估隐私泄露程度。为此,本文提出FIA-Flow——一种黑盒特征逆向攻击框架,可从中间特征中实现高保真图像重建。为利用中间特征中的语义信息,设计了潜在特征空间对齐模块(LFSAM),弥合中间特征空间与潜在空间之间的语义鸿沟;为解决分布不匹配问题,提出确定性逆向流匹配(DIFM),通过一步推断将离流形特征投影至目标流形。该解耦设计简化学习过程,支持仅用少量图像-特征对有效训练。为从人类视角量化隐私泄露,引入基于大规模视觉语言模型的两项新指标。实验表明,FIA-Flow在多种模型(AlexNet、ResNet、Swin Transformer、DINO、YOLO11)及不同层上均实现更忠实、语义一致的特征逆向,揭示分割式神经网络的隐私威胁比以往认知更为严重。

原文摘要 · Abstract (English)

Split DNNs enable edge devices by offloading intensive computation to a cloud server, but this paradigm exposes privacy vulnerabilities, as the intermediate features can be exploited to reconstruct the private inputs via Feature Inversion Attack (FIA). Existing FIA methods often produce limited reconstruction quality, making it difficult to assess the true extent of privacy leakage. To reveal the privacy risk of the leaked features, we introduce FIA-Flow, a black-box FIA framework that achieves high-fidelity image reconstruction from intermediate features. To exploit the semantic information within intermediate features, we design a Latent Feature Space Alignment Module (LFSAM) to bridge the semantic gap between the intermediate feature space and the latent space. Furthermore, to rectify distributional mismatch, we develop Deterministic Inversion Flow Matching (DIFM), which projects off-manifold features onto the target manifold with one-step inference. This decoupled design simplifies learning and enables effective training with few image-feature pairs. To quantify privacy leakage from a human perspective, we also propose two metrics based on a large vision-language model. Experiments show that FIA-Flow achieves more faithful and semantically aligned feature inversion across various models (AlexNet, ResNet, Swin Transformer, DINO, and YOLO11) and layers, revealing a more severe privacy threat in Split DNNs than previously recognized.

隐私攻击特征逆向分割网络黑盒攻击

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。