A split neural network with a secret output-flip signal is claimed to protect input, output, and model privacy without cryptography, but the security argument conflates non-uniqueness with privacy and ignores known inversion attacks.
Title resolution pending
1 Pith paper cite this work. Polarity classification is still indexing.
1
Pith paper citing it
fields
cs.CR 1years
2019 1verdicts
REJECT 1representative citing papers
citing papers explorer
-
A Novel Privacy-Preserving Deep Learning Scheme without Using Cryptography Component
A split neural network with a secret output-flip signal is claimed to protect input, output, and model privacy without cryptography, but the security argument conflates non-uniqueness with privacy and ignores known inversion attacks.