Pith. sign in

REVIEW 3 cited by

Practical Defences Against Model Inversion Attacks for Split Neural Networks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2104.05743 v2 pith:OJGT7DT4 submitted 2021-04-12 cs.LG cs.CRcs.DC

classification cs.LGcs.CRcs.DC
keywords modelattackinversionmethoddatasplitacceptableaccuracy
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We describe a threat model under which a split network-based federated learning system is susceptible to a model inversion attack by a malicious computational server. We demonstrate that the attack can be successfully performed with limited knowledge of the data distribution by the attacker. We propose a simple additive noise method to defend against model inversion, finding that the method can significantly reduce attack efficacy at an acceptable accuracy trade-off on MNIST. Furthermore, we show that NoPeekNN, an existing defensive method, protects different information from exposure, suggesting that a combined defence is necessary to fully protect private user data.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Model Inversion in Split Learning for Personalized LLMs: New Insights from Information Bottleneck Theory

    cs.LG 2025-01 conditional novelty 6.0 of 10

    RevertLM reconstructs private text from intermediate LLM representations in split learning using a projection into embedding space plus a generative decoder, outperforming prior embedding-only attacks.

  2. Revisiting the Privacy Risks of Split Inference: A GAN-Based Data Reconstruction Attack via Progressive Feature Optimization

    cs.CV 2025-08 reject novelty 4.0 of 10

    PFO improves GAN-based split-inference reconstruction via progressive intermediate-feature optimization, but its quantitative claims rest on internally inconsistent metric tables.

  3. Deep Learning Model Inversion Attacks and Defenses: A Comprehensive Survey

    cs.CR 2025-01 accept novelty 4.0 of 10

    A structured literature review that taxonomizes model inversion attacks and defenses and provides a public resource repository.

Pith tools