发表机构
Nanjing University of Aeronautics and Astronautics(南京航空航天大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究探讨模型量化对模型反演攻击的影响,提出一种隐私感知的训练后量化方法,通过任务敏感比特分配和联合优化,在保持高精度的同时显著降低反演攻击成功率。
AI 中文摘要
模型量化通过降低神经网络权重和激活值的数值精度来减少存储和计算成本。模型反演攻击则从模型输出或中间特征中恢复或重建敏感训练数据或推理输入,因此量化也可能改变这些攻击的有效性。然而,仍有两个问题尚未解决:模型量化如何影响模型反演?数据特征如何影响这种关系?为解决第一个问题,我们界定了量化引起的输入与由预测概率定义的分类变量之间互信息的变化,从而区分信息效应与攻击优化障碍。为解决第二个问题,我们识别了特征分布和反演结果中依赖于数据的变化,并观察到在4比特时存在显著的量化敏感性差异。这些见解指导了一种隐私感知的训练后量化方法,该方法在恢复效用的同时提高了抗反演能力。它使用基于Fisher的任务敏感性代理进行预算感知的比特分配,校准激活范围,并联合优化权重和激活尺度以及权重舍入决策,同时结合任务恢复和几何保持目标以及尺度和舍入正则化。实验涵盖了多种指标、神经网络架构以及人脸、掌纹和虹膜识别任务。在ResNet-50上,Palm在4比特时将RL-MIA的严格成功率从54%降至26%,而相对于FP32,准确率从99.01%降至96.55%。我们的方法还支持输出级防御:在4.5比特下,将Stealthy Shield Defense(SSD,epsilon = 0.1)添加到Iris,可将BREP-MI的严格成功率从63.33%降至37.33%,而相对于仅量化,准确率从92.8%降至87.6%。
英文摘要
Model quantization reduces the numerical precision of neural network weights and activations to lower storage and computational costs. Model inversion attacks recover or reconstruct sensitive training data or inference inputs from model outputs or intermediate features, so quantization may also alter their effectiveness. However, two questions remain unresolved: How does model quantization affect model inversion? How do data characteristics influence this relationship? To address the first, we bound quantization-induced changes in mutual information between inputs and a categorical variable defined by prediction probabilities, distinguishing informational effects from attack optimization obstacles. To address the second, we identify data-dependent changes in feature distributions and inversion outcomes, with pronounced quantization sensitivity differences at 4 bits. These insights guide a privacy-aware post-training quantization method that improves inversion resistance while recovering utility. It uses a Fisher-type task-sensitivity proxy for budget-aware bit allocation, calibrates activation ranges, and jointly optimizes weight and activation scales and weight-rounding decisions with task-recovery and geometry-retention objectives and scale and rounding regularization. Experiments cover multiple metrics, neural network architectures, and face, palmprint, and iris recognition tasks. On ResNet-50, Palm at 4 bits reduces RL-MIA's strict success from 54% to 26%, while accuracy decreases from 99.01% to 96.55% relative to FP32. Our method also supports output-level defenses: adding Stealthy Shield Defense (SSD, epsilon = 0.1) to Iris at 4.5 bits reduces BREP-MI's strict success from 63.33% to 37.33%, while accuracy decreases from 92.8% to 87.6% relative to quantization alone.