错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Systematic Evaluation of Robustness Against Model Inversion Attacks on Split Learning

  • Hyunsik Na,
  • Yoonju Oh,
  • Wonho Lee,
  • Daeseon Choi

摘要

Split learning is a new training paradigm that divides a neural network into two parts and performs operations on the client and server, respectively. However, it does not directly transmit the client’s original data to the server, and the intermediate features transmitted by the client allow an attacker to guess the original data via model inversion attacks. In this study, we conducted a quantitative evaluation to compare the performances of three existing defense technologies to prevent such threats to data privacy. For systematic experiments, we used two datasets and three target classification models and measured how well previous defenses maintained model accuracy and resisted model inversion attacks. Our results showed that Laplacian noise-based defense has little practical effect, NoPeekNN has a large performance variation, and differential privacy is somewhat helpful in defense; however, the larger the client-side model, the lower the task performance. Finally, further research is needed to overcome the limitations of previous defenses.