用密钥扰动中间特征,让医疗图像共享更安全且不降性能。
Keyed Nonlinear Transform: Lightweight Privacy-Enhancing Feature Sharing for Medical Image Analysis

- 通过密钥控制的非线性变换,对中间特征进行扰动
- 重识别准确率从0.635降至0.586,降低36%身份泄露风险
- 无需重新训练,适用于图像分割等多任务场景
通过拆分推理实现特征共享,为资源受限医院提供了轻量级替代联邦学习的方案,但传输的特征仍存在患者身份泄露风险,且缺乏可控共享机制。本文提出关键非线性变换(KNT),一种即插即用的特征转换方法,对中间表示施加密钥条件化的混淆。KNT将重识别AUC从0.635降至0.586,相当于高出随机水平的身份信号减少36%,仅引入0.15毫秒CPU开销,无需主干网络重训练,且分类性能下降不超过1.0个百分点。分析表明,KNT的非线性变换阻止了闭式反演,即使在密钥完全泄露时,恢复也需依赖迭代梯度优化,显著提升反演难度。该变换同样适用于密集预测任务,在皮肤病变分割上仅导致4.4个百分点的Dice分数下降,无需重训练。这些结果使KNT成为拆分推理部署中实用高效的隐私保护层。
原文摘要 · Abstract (English)
Feature sharing via split inference offers a lightweight alternative to federated learning for resource-constrained hospitals, but transmitted features still leak patient identity information and lack practical mechanisms for controlled feature sharing. We propose Keyed Nonlinear Transform (KNT), a drop-in feature transformation that applies key-conditioned obfuscation to intermediate representations. KNT reduces re-identification AUC from 0.635 to 0.586, corresponding to a 36% reduction in above-chance identity signal, while introducing only 0.15 ms CPU overhead, without backbone retraining, and preserving classification performance within 1.0 pp. Our analysis shows that KNT's nonlinear transform prevents closed-form inversion and shifts recovery to iterative gradient-based optimization under full key compromise, substantially increasing inversion difficulty. The same transform generalizes to dense prediction tasks, incurring only a 4.4 pp Dice reduction on skin-lesion segmentation without retraining. These results position KNT as a practical and efficient privacy layer for split inference deployments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。