用拓扑复杂度识别隐私风险层,提升分片学习安全性
BettiSplit: Topology-Guided Privacy-Aware Split Learning Against Feature Inversion and Gradient Leakage

- 基于激活张量的拓扑复杂度动态定位隐私敏感层
- 在深度关键点上特征反演相似度达0.98 SSIM,风险非均匀分布
- 无需实际攻击即可选择安全分片位置,兼顾隐私与模型性能
分片学习通过将神经网络分割在客户端与服务器间实现协作训练,但不当的分片位置可能引发中间表示的严重隐私泄露。本文提出基于被挤压激活持久贝蒂复杂度的拓扑引导隐私感知分片学习框架。通过逐层分析发现,隐私风险在各层间高度不均,并存在架构深度无法捕捉的剧烈转变区域;在深层隐私关键分片点,特征反演保真度从可忽略提升至高达0.98 SSIM。进一步证明,贝蒂复杂度能一致识别出跨架构与数据集的高隐私泄露表征区域。据此提出BettiSafe策略,无需显式攻击即可定位隐私敏感层,相比基于深度的启发式方法,抗特征反演能力提升2至5倍,同时保持分类准确率。此外,基于贝蒂的正则化使反演难度增加近5倍,且不损害模型效用,实现良好的隐私-效用权衡。结果表明,拓扑复杂度是真实协同系统中安全、自适应、表征感知分片学习的有力结构描述符。
原文摘要 · Abstract (English)
Split learning enables collaborative model training by partitioning neural networks across clients and servers. However, improper split placement can lead to severe privacy leakage through intermediate representations. In this work, we propose a topology-guided framework for privacy-aware split learning based on the persistent Betti complexity of smashed activations. Through comprehensive layer-wise analysis, we show that privacy risk in split learning is highly non-uniform across layers and exhibits sharp transition regions that are not captured by architectural depth alone. In particular, feature inversion fidelity increases from negligible reconstruction to as high as 0.98 SSIM at deeper, privacy-critical split points. We further demonstrate that Betti complexity consistently identifies representation regimes associated with elevated feature-space privacy leakage across architectures and datasets. Leveraging this observation, we introduce BettiSafe, a topology-guided split selection strategy that identifies privacy-sensitive layers without requiring explicit attack execution. BettiSafe improves resistance to feature inversion by 2 to 5 times compared to depth-based heuristics while preserving classification accuracy. In addition, Betti-based regularisation increases inversion difficulty by nearly 5 x without degrading model utility, enabling a favourable privacy utility tradeoff. Overall, our results highlight topological complexity as a promising structural descriptor for secure, adaptive, and representation-aware split learning in real-world collaborative systems
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。