Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Qiu, Yixiang, Liu, Yanhan, Yu, Hongyao, Fang, Hao, Chen, Bin, Xia, Shu-Tao, Xu, Ke
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916923372994560
author Qiu, Yixiang
Liu, Yanhan
Yu, Hongyao
Fang, Hao
Chen, Bin
Xia, Shu-Tao
Xu, Ke
author_facet Qiu, Yixiang
Liu, Yanhan
Yu, Hongyao
Fang, Hao
Chen, Bin
Xia, Shu-Tao
Xu, Ke
contents The growing complexity of Deep Neural Networks (DNNs) has led to the adoption of Split Inference (SI), a collaborative paradigm that partitions computation between edge devices and the cloud to reduce latency and protect user privacy. However, recent advances in Data Reconstruction Attacks (DRAs) reveal that intermediate features exchanged in SI can be exploited to recover sensitive input data, posing significant privacy risks. Existing DRAs are typically effective only on shallow models and fail to fully leverage semantic priors, limiting their reconstruction quality and generalizability across datasets and model architectures. In this paper, we propose a novel GAN-based DRA framework with Progressive Feature Optimization (PFO), which decomposes the generator into hierarchical blocks and incrementally refines intermediate representations to enhance the semantic fidelity of reconstructed images. To stabilize the optimization and improve image realism, we introduce an L1-ball constraint during reconstruction. Extensive experiments show that our method outperforms prior attacks by a large margin, especially in high-resolution scenarios, out-of-distribution settings, and against deeper and more complex DNNs.
format Preprint
id arxiv_https___arxiv_org_abs_2508_20613
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization
Qiu, Yixiang
Liu, Yanhan
Yu, Hongyao
Fang, Hao
Chen, Bin
Xia, Shu-Tao
Xu, Ke
Computer Vision and Pattern Recognition
Cryptography and Security
The growing complexity of Deep Neural Networks (DNNs) has led to the adoption of Split Inference (SI), a collaborative paradigm that partitions computation between edge devices and the cloud to reduce latency and protect user privacy. However, recent advances in Data Reconstruction Attacks (DRAs) reveal that intermediate features exchanged in SI can be exploited to recover sensitive input data, posing significant privacy risks. Existing DRAs are typically effective only on shallow models and fail to fully leverage semantic priors, limiting their reconstruction quality and generalizability across datasets and model architectures. In this paper, we propose a novel GAN-based DRA framework with Progressive Feature Optimization (PFO), which decomposes the generator into hierarchical blocks and incrementally refines intermediate representations to enhance the semantic fidelity of reconstructed images. To stabilize the optimization and improve image realism, we introduce an L1-ball constraint during reconstruction. Extensive experiments show that our method outperforms prior attacks by a large margin, especially in high-resolution scenarios, out-of-distribution settings, and against deeper and more complex DNNs.
title Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization
topic Computer Vision and Pattern Recognition
Cryptography and Security
url https://arxiv.org/abs/2508.20613