relay 会泄露语义信息,新方法让合法接收方能解码,但中继无法窃取。
Semantic Leakage and Privacy Preservation in Relay-Assisted Semantic Communications

- 在中继节点上训练对抗性窃听者,动态优化隐私保护策略。
- 在不同信道下,合法接收方与窃听者间语义准确率差距显著增大。
- 保护隐蔽性强,信号重建质量高,仅抑制语义泄露。
语义通信(SemCom)作为一种新兴范式,优先传输任务相关的信息而非原始数据,在资源和信道受限条件下实现高效、鲁棒通信。本文研究了中继辅助语义通信系统的隐私问题,发现中继节点虽无源数据访问权限,仍能通过学习的潜在表示可靠推断语义内容,并实现与合法接收方性能相当的信号重构,揭示了语义表示的根本隐私漏洞。为解决该问题,提出一种迭代对抗训练框架,显式考虑在中继处训练强而自适应的窃听者。该方法交替优化窃听功能与合法系统,使语义表示在保持合法接收方解码性能的同时,显著降低中继端的语义推断能力。在不同信道条件下,合法接收方与窃听者间的语义准确率差距显著扩大。重要的是,该保护以隐蔽方式实现,重建保真度高,仅选择性抑制语义泄漏。
原文摘要 · Abstract (English)
Semantic communication (SemCom) has emerged as a promising paradigm in which the transmission of task-relevant information is prioritized over raw data, enabling efficient and robust communication under resource and channel constraints. In this paper, the privacy implications of relay-assisted SemCom systems are studied, where the intermediate relay node operates directly on learned latent representations. It is shown that the relay, even without access to source data, can reliably infer semantic meaning and reconstruct signals with performance comparable to that of the legitimate receiver, revealing a fundamental privacy vulnerability of semantic representations. To address this issue, an iterative adversarial training framework is proposed in which a strong, adaptively trained eavesdropper at the relay is explicitly accounted for. The proposed approach alternates between optimizing the relay's eavesdropping function and the legitimate system, resulting in representations that preserve semantic decoding performance at the intended receiver while degrading semantic inference at the relay. The semantic accuracy gap between the legitimate receiver and the eavesdropper is significantly enlarged across channel conditions. Importantly, this protection is achieved in a stealthy manner, with high reconstruction fidelity maintained while semantic leakage is selectively suppressed.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。