PATROL: Privacy-Oriented Pruning for Collaborative Inference Against Model Inversion Attacks

07/20/2023
by   Shiwei Ding, et al.
0

Collaborative inference has been a promising solution to enable resource-constrained edge devices to perform inference using state-of-the-art deep neural networks (DNNs). In collaborative inference, the edge device first feeds the input to a partial DNN locally and then uploads the intermediate result to the cloud to complete the inference. However, recent research indicates model inversion attacks (MIAs) can reconstruct input data from intermediate results, posing serious privacy concerns for collaborative inference. Existing perturbation and cryptography techniques are inefficient and unreliable in defending against MIAs while performing accurate inference. This paper provides a viable solution, named PATROL, which develops privacy-oriented pruning to balance privacy, efficiency, and utility of collaborative inference. PATROL takes advantage of the fact that later layers in a DNN can extract more task-specific features. Given limited local resources for collaborative inference, PATROL intends to deploy more layers at the edge based on pruning techniques to enforce task-specific features for inference and reduce task-irrelevant but sensitive features for privacy preservation. To achieve privacy-oriented pruning, PATROL introduces two key components: Lipschitz regularization and adversarial reconstruction training, which increase the reconstruction errors by reducing the stability of MIAs and enhance the target inference model by adversarial training, respectively.

READ FULL TEXT

page 1

page 6

research
12/13/2022

Privacy-preserving Security Inference Towards Cloud-Edge Collaborative Using Differential Privacy

Cloud-edge collaborative inference approach splits deep neural networks ...
research
07/16/2022

A Survey on Collaborative DNN Inference for Edge Intelligence

With the vigorous development of artificial intelligence (AI), the intel...
research
04/08/2021

Can Differential Privacy Practically Protect Collaborative Deep Learning Inference for the Internet of Things?

Collaborative inference has recently emerged as an intriguing framework ...
research
09/06/2023

Roulette: A Semantic Privacy-Preserving Device-Edge Collaborative Inference Framework for Deep Learning Classification Tasks

Deep learning classifiers are crucial in the age of artificial intellige...
research
05/10/2021

AppealNet: An Efficient and Highly-Accurate Edge/Cloud Collaborative Architecture for DNN Inference

This paper presents AppealNet, a novel edge/cloud collaborative architec...
research
05/13/2023

MetaMorphosis: Task-oriented Privacy Cognizant Feature Generation for Multi-task Learning

With the growth of computer vision applications, deep learning, and edge...
research
04/22/2022

A Tale of Two Models: Constructing Evasive Attacks on Edge Models

Full-precision deep learning models are typically too large or costly to...

Please sign up or login with your details

Forgot password? Click here to reset