AttrLeaks on the Edge: Exploiting Information Leakage from Privacy-Preserving Co-inference

被引:52
|
作者
Wang, Zhibo [1 ,2 ]
Liu, Kaixin [1 ]
Hu, Jiahui [2 ]
Ren, Ju [3 ]
Guo, Hengchang [1 ]
Yuan, Wei [1 ]
机构
[1] Wuhan Univ, Sch Cyber Sci & Engn, Wuhan 430072, Peoples R China
[2] Zhejiang Univ, Sch Cyber Sci & Technol, Hangzhou 310027, Zhejiang, Peoples R China
[3] Tsinghua Univ, Dept Comp Sci & Technol, Beijing 100084, Peoples R China
基金
中国国家自然科学基金; 国家重点研发计划;
关键词
Deep learning; Privacy; Collaboration; Transforms; Feature extraction; Prediction algorithms; Iron; Collaborative inference; Private information leakage; Attribute inference attack;
D O I
10.23919/cje.2022.00.031
中图分类号
TM [电工技术]; TN [电子技术、通信技术];
学科分类号
0808 ; 0809 ;
摘要
Collaborative inference (co-inference) accelerates deep neural network inference via extracting representations at the device and making predictions at the edge server, which however might disclose the sensitive information about private attributes of users (e.g., race). Although many privacy-preserving mechanisms on co-inference have been proposed to eliminate privacy concerns, privacy leakage of sensitive attributes might still happen during inference. In this paper, we explore privacy leakage against the privacy-preserving co-inference by decoding the uploaded representations into a vulnerable form. We propose a novel attack framework named AttrLeaks, which consists of the shadow model of feature extractor (FE), the susceptibility reconstruction decoder, and the private attribute classifier. Based on our observation that values in inner layers of FE (internal representation) are more sensitive to attack, the shadow model is proposed to simulate the FE of the victim in the black-box scenario and generates the internal representations. Then, the susceptibility reconstruction decoder is designed to transform the uploaded representations of the victim into the vulnerable form, which enables the malicious classifier to easily predict the private attributes. Extensive experimental results demonstrate that AttrLeaks outperforms the state of the art in terms of attack success rate.
引用
收藏
页码:1 / 12
页数:12
相关论文
共 50 条
  • [21] EPIDL: Towards efficient and privacy-preserving inference in deep learning
    Nie, Chenfei
    Zhou, Zhipeng
    Dong, Mianxiong
    Ota, Kaoru
    Li, Qiang
    CONCURRENCY AND COMPUTATION-PRACTICE & EXPERIENCE, 2024, 36 (14)
  • [22] PPTIF: Privacy-Preserving Transformer Inference Framework for Language Translation
    Liu, Yanxin
    Su, Qianqian
    IEEE ACCESS, 2024, 12 : 48881 - 48897
  • [23] Adversarial Privacy-Preserving Graph Embedding Against Inference Attack
    Li, Kaiyang
    Luo, Guangchun
    Ye, Yang
    Li, Wei
    Ji, Shihao
    Cai, Zhipeng
    IEEE INTERNET OF THINGS JOURNAL, 2021, 8 (08) : 6904 - 6915
  • [24] Local Information Privacy and Its Application to Privacy-Preserving Data Aggregation
    Jiang, Bo
    Li, Ming
    Tandon, Ravi
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2022, 19 (03) : 1918 - 1935
  • [25] Privacy-Preserving Audio Classification Using Variational Information Feature Extraction
    Nelus, Alexandru
    Martin, Rainer
    IEEE-ACM TRANSACTIONS ON AUDIO SPEECH AND LANGUAGE PROCESSING, 2021, 29 : 2864 - 2877
  • [26] Privacy-Preserving OLAP: An Information-Theoretic Approach
    Zhang, Nan
    Zhao, Wei
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2011, 23 (01) : 122 - 138
  • [27] PRIVATUBE: Privacy-Preserving Edge-Assisted Video Streaming
    Da Silva, Simon
    Ben Mokhtar, Sonia
    Contiu, Stefan
    Negru, Daniel
    Reveillere, Laurent
    Riviere, Etienne
    MIDDLEWARE'19: PROCEEDINGS OF THE 2019 MIDDLEWARE'19: 20TH INTERNATIONAL MIDDLEWARE CONFERENCE, 2019, : 189 - 201
  • [28] PFLF: Privacy-Preserving Federated Learning Framework for Edge Computing
    Zhou, Hao
    Yang, Geng
    Dai, Hua
    Liu, Guoxiu
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2022, 17 : 1905 - 1918
  • [29] Privacy Partition: A Privacy-preserving Framework for Deep Neural Networks in Edge Networks
    Chi, Jianfeng
    Owusu, Emmanuel
    Yin, Xuwang
    Yu, Tong
    Chan, William
    Liu, Yiming
    Liu, Haodong
    Chen, Jiasen
    Sim, Swee
    Iyengar, Vibha
    Tague, Patrick
    Tian, Yuan
    2018 THIRD IEEE/ACM SYMPOSIUM ON EDGE COMPUTING (SEC), 2018, : 378 - 380
  • [30] Privacy-preserving Information Security for the Energy Grid of Things
    Alsaid, Mohammed
    Bulusu, Nirupama
    Bargouti, Abdullah
    Fernando, N. Sonali
    Acken, John M.
    Slay, Tylor
    Bass, Robert B.
    PROCEEDINGS OF THE 11TH INTERNATIONAL CONFERENCE ON SMART CITIES AND GREEN ICT SYSTEMS (SMARTGREENS), 2022, : 110 - 116