arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

稀疏协同推理的隐私研究

A Privacy Study of Sparse Collaborative Inference

Maximilian Andreas Hoefler, Karsten Mueller, Wojciech Samek

arXiv 2608.16236首次发表:更新:

发表机构

Fraunhofer Heinrich Hertz Institute; Technical University of Berlin; Berlin Institute for the Foundations of Learning and Data (BIFOLD)(弗劳恩霍夫海因里希·赫兹研究所; 柏林工业大学; 柏林学习与数据基础研究所(BIFOLD))

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对稀疏协同推理,发现稀疏激活的位置会造成严重隐私泄露,需将其视为敏感数据审计。

AI 中文摘要

协同推理(CI)将模型拆分到边缘设备和服务器之间,客户端计算中间激活值并传输,服务器完成计算。这引发两个问题:传输的通信成本,以及传输可能泄露输入的隐私信息。近期研究通过稀疏化激活值并对结果进行熵编码来降低该成本,同时有观点认为稀疏性可提升隐私性,直觉是传输更少的值会泄露更少的输入信息。我们通过将稀疏激活分解为保留值及其位置集合,并分别从每个组件重建输入,来验证这一观点。研究发现,稀疏化降低的隐私泄露远少于其降低的传输成本,且剩余风险转移到了位置上,而先前分析将位置视为解码的辅助信息。在自然图像和人脸数据集上,仅位置就构成严重隐私风险,可实现高保真重建和个体重识别。即使传输成本和任务效用都较低,位置的泄露仍然存在。我们得出结论:在协同推理场景中,稀疏激活的位置应被视为敏感传输数据并进行仔细审计。代码可在该 https URL 获取。

英文摘要

Collaborative inference (CI) splits a model between an edge device and a server, whereby the client computes an intermediate activation, transmits it, and the server completes the computation. This raises two concerns, the communication cost of the transmission and the risk that it reveals private information about the input. Recent work reduces this cost by sparsifying activations and entropy-coding the result. Sparsity has also been argued to improve privacy, on the intuition that transmitting fewer values reveals less about the input. We test this claim by decomposing the sparse activation into the retained values and the set of positions they occupy, and by reconstructing inputs from each component in isolation. We find that sparsification reduces the leakage far less than it reduces the transmission cost, and that the remaining risk shifts to the positions, which prior analyses treat as side information for decoding. Across natural-image and face datasets, the positions alone constitute a serious privacy risk, enabling high-fidelity reconstructions and re-identification of individuals. The leakage from the positions persists even when both the transmission cost and the task utility are low. We conclude that the positions of sparse activations should be treated as sensitive transmitted data and audited carefully in the context of collaborative inference. Code is available at https://github.com/an7123/Privacy-Study-Sparse-CI.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑