REVIEW 3 cited by
Practical Defences Against Model Inversion Attacks for Split Neural Networks
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
We describe a threat model under which a split network-based federated learning system is susceptible to a model inversion attack by a malicious computational server. We demonstrate that the attack can be successfully performed with limited knowledge of the data distribution by the attacker. We propose a simple additive noise method to defend against model inversion, finding that the method can significantly reduce attack efficacy at an acceptable accuracy trade-off on MNIST. Furthermore, we show that NoPeekNN, an existing defensive method, protects different information from exposure, suggesting that a combined defence is necessary to fully protect private user data.
Forward citations
Cited by 3 Pith papers
-
Model Inversion in Split Learning for Personalized LLMs: New Insights from Information Bottleneck Theory
RevertLM reconstructs private text from intermediate LLM representations in split learning using a projection into embedding space plus a generative decoder, outperforming prior embedding-only attacks.
-
Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization
PFO improves GAN-based split-inference reconstruction via progressive intermediate-feature optimization, but its quantitative claims rest on internally inconsistent metric tables.
-
Deep Learning Model Inversion Attacks and Defenses: A Comprehensive Survey
A structured literature review that taxonomizes model inversion attacks and defenses and provides a public resource repository.
Discussion (0). Continue with ORCID to comment.