Ensembler: Protect Collaborative Inference Privacy from Model Inversion Attack via Selective Ensemble

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Liu, Dancheng, Xu, Chenhui, Li, Jiajie, Nassereldine, Amir, Xiong, Jinjun
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866929642888232960
author Liu, Dancheng
Xu, Chenhui
Li, Jiajie
Nassereldine, Amir
Xiong, Jinjun
author_facet Liu, Dancheng
Xu, Chenhui
Li, Jiajie
Nassereldine, Amir
Xiong, Jinjun
contents For collaborative inference through a cloud computing platform, it is sometimes essential for the client to shield its sensitive information from the cloud provider. In this paper, we introduce Ensembler, an extensible framework designed to substantially increase the difficulty of conducting model inversion attacks by adversarial parties. Ensembler leverages selective model ensemble on the adversarial server to obfuscate the reconstruction of the client's private information. Our experiments demonstrate that Ensembler can effectively shield input images from reconstruction attacks, even when the client only retains one layer of the network locally. Ensembler significantly outperforms baseline methods by up to 43.5% in structural similarity while only incurring 4.8% time overhead during inference.
format Preprint
id arxiv_https___arxiv_org_abs_2401_10859
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Ensembler: Protect Collaborative Inference Privacy from Model Inversion Attack via Selective Ensemble
Liu, Dancheng
Xu, Chenhui
Li, Jiajie
Nassereldine, Amir
Xiong, Jinjun
Cryptography and Security
Machine Learning
For collaborative inference through a cloud computing platform, it is sometimes essential for the client to shield its sensitive information from the cloud provider. In this paper, we introduce Ensembler, an extensible framework designed to substantially increase the difficulty of conducting model inversion attacks by adversarial parties. Ensembler leverages selective model ensemble on the adversarial server to obfuscate the reconstruction of the client's private information. Our experiments demonstrate that Ensembler can effectively shield input images from reconstruction attacks, even when the client only retains one layer of the network locally. Ensembler significantly outperforms baseline methods by up to 43.5% in structural similarity while only incurring 4.8% time overhead during inference.
title Ensembler: Protect Collaborative Inference Privacy from Model Inversion Attack via Selective Ensemble
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2401.10859