Pith. sign in

REVIEW 1 cited by

Vicious Classifiers: Assessing Inference-time Data Reconstruction Risk in Edge Computing

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2212.04223 v3 pith:UGNMHDRZ submitted 2022-12-08 cs.LG cs.CRcs.ITmath.IT

classification cs.LGcs.CRcs.ITmath.IT
keywords modelcomputingdataedgeinferenceinputoutputsreconstruction
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Privacy-preserving inference in edge computing paradigms encourages the users of machine-learning services to locally run a model on their private input and only share the models outputs for a target task with the server. We study how a vicious server can reconstruct the input data by observing only the models outputs while keeping the target accuracy very close to that of a honest server by jointly training a target model (to run at users' side) and an attack model for data reconstruction (to secretly use at servers' side). We present a new measure to assess the inference-time reconstruction risk. Evaluations on six benchmark datasets show the model's input can be approximately reconstructed from the outputs of a single inference. We propose a primary defense mechanism to distinguish vicious versus honest classifiers at inference time. By studying such a risk associated with emerging ML services our work has implications for enhancing privacy in edge computing. We discuss open challenges and directions for future studies and release our code as a benchmark for the community at https://github.com/mmalekzadeh/vicious-classifiers .

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Inference Privacy: Properties and Mechanisms

    cs.CR 2024-11 conditional novelty 3.0 of 10

    Inference Privacy requires that a model's output distributions for any two inputs within a chosen radius alpha are almost identical, and it is implemented by calibrating input or output noise with standard differentia...

Pith tools