arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

BettiSplit:基于拓扑结构引导的隐私感知分割学习方法,可抵御特征反转和梯度泄露

BettiSplit: Topology-Guided Privacy-Aware Split Learning Against Feature Inversion and Gradient Leakage

Akarsh K. Nair, Muhammad Arifur Rahman, David Brown, Mufti Mahmud

arXiv 2607.24556首次发表:更新:

发表机构

Nottingham Trent University; King Fahd University of Petroleum & Minerals(诺丁汉特伦特大学; 法赫德国王石油与矿业大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究针对分割学习中因分割位置不当致隐私泄露问题,基于持久贝蒂复杂度提出拓扑引导框架,引入BettiSafe策略,提升对特征反转抗性,保持准确率,还通过正则化实现隐私效用权衡,凸显拓扑复杂度在分割学习中的作用。

AI 中文摘要

分割学习通过在客户端和服务器之间划分神经网络来实现协作模型训练。然而,不当的分割位置会导致通过中间表示严重的隐私泄露。本文中,我们基于粉碎激活点的持久贝蒂复杂度,提出了一种用于隐私感知分割学习的拓扑引导框架。通过全面的逐层分析,我们表明:分割学习中的隐私风险在各层之间高度不均匀,且存在仅靠架构深度无法捕捉的尖锐过渡区域。特别是在更深层次、隐私关键的分割点,特征反转保真度从可忽略不计的重建提升到高达0.98的结构相似性指数(SSIM)。我们进一步证明,贝蒂复杂度始终能识别跨架构和数据集与特征空间隐私泄露增加相关的表示机制。利用这一观察结果,我们引入了BettiSafe,一种拓扑引导的分割选择策略,无需明确执行攻击即可识别隐私敏感层。与基于深度的启发式方法相比,BettiSafe将对特征反转的抗性提高了2至5倍,同时保持分类准确率。此外,基于贝蒂的正则化在不降低模型效用的情况下,将反转难度提高了近5倍,实现了良好的隐私效用权衡。总的来说,我们的结果突出了拓扑复杂度作为一种有前景的结构描述符,可用于现实世界协作系统中的安全、自适应和表示感知分割学习。

英文摘要

Split learning enables collaborative model training by partitioning neural networks across clients and servers. However, improper split placement can lead to severe privacy leakage through intermediate representations. In this work, we propose a topology-guided framework for privacy-aware split learning based on the persistent Betti complexity of smashed activations. Through comprehensive layer-wise analysis, we show that privacy risk in split learning is highly non-uniform across layers and exhibits sharp transition regions that are not captured by architectural depth alone. In particular, feature inversion fidelity increases from negligible reconstruction to as high as 0.98 SSIM at deeper, privacy-critical split points. We further demonstrate that Betti complexity consistently identifies representation regimes associated with elevated feature-space privacy leakage across architectures and datasets. Leveraging this observation, we introduce BettiSafe, a topology-guided split selection strategy that identifies privacy-sensitive layers without requiring explicit attack execution. BettiSafe improves resistance to feature inversion by 2 to 5 times compared to depth-based heuristics while preserving classification accuracy. In addition, Betti-based regularisation increases inversion difficulty by nearly 5 x without degrading model utility, enabling a favourable privacy utility tradeoff. Overall, our results highlight topological complexity as a promising structural descriptor for secure, adaptive, and representation-aware split learning in real-world collaborative systems

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑