arrow
返回

TrapMI: A Data Protection Method to Resist Model Inversion Attacks in Split Learning

delete2025-01-01
delete0
delete
OA
AI
H
Hyunsik Na
D
Daeseon Choi *
DOI:10.1109/ACCESS.2025.3545597delete
delete原文链接
delete原文求助
delete分享
delete收藏
摘要

摘要

En 中文
Split learning is a neural network training approach that can overcome the limitations of traditional deep neural networks in edge artificial intelligence environments. It offers the advantage of privacy protection because it transmits intermediate features that are calculated via the client-side model and the client does not need to send the original input data to the server. However, concerns remain regarding data privacy leakage because an attacker can still attempt model inversion attacks based on the intermediate features. We introduce several shortcomings of existing defense techniques for such attacks and present a new defense approach called TrapMI. The proposed method can induce an attacker to generate a class-specific target image that appears different from the original image when inverting the input image. We analyze the performance through quantitative and qualitative evaluations. Furthermore, the AutoGenerator is proposed to overcome the problem whereby the client cannot perform modulation that requires the target image because the class of the input image is unknown during this phase. De-identified images are automatically modulated in the inference phase using this approach. The proposed method was evaluated on two datasets, three classification models, and three split points. Its resistance was measured using a deeper and stronger inverse model than those in previous studies. Overall, the proposed method ensures data privacy protection at a significantly higher level while maintaining a similar task performance to that of existing defense technologies.
Keyword:
Servers
Data models
Training
Data privacy
Noise
Image reconstruction
Computational modeling
Protection
Feature extraction
Artificial neural networks
Artificial intelligence security
data privacy protection
model inversion attack
split learning

期刊

IEEE Access 封面图
IEEE Access
IF:
3.6
论文数:
9.8W
被引数:
29.4W

机构

S
Soongsil University
学者数:
3.4K
论文数: 3.5K
被引数: 3.2K
引用论文

引用论文

暂无论文信息