Pith. sign in

REVIEW 3 cited by

Passive Inference Attacks on Split Learning via Adversarial Regularization

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.10483 v6 pith:YZ6DZRXY submitted 2023-10-16 cs.CR cs.LG

classification cs.CRcs.LG
keywords attacksprivatesdarattackclientlearningsplitu-shaped
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Split Learning (SL) has emerged as a practical and efficient alternative to traditional federated learning. While previous attempts to attack SL have often relied on overly strong assumptions or targeted easily exploitable models, we seek to develop more capable attacks. We introduce SDAR, a novel attack framework against SL with an honest-but-curious server. SDAR leverages auxiliary data and adversarial regularization to learn a decodable simulator of the client's private model, which can effectively infer the client's private features under the vanilla SL, and both features and labels under the U-shaped SL. We perform extensive experiments in both configurations to validate the effectiveness of our proposed attacks. Notably, in challenging scenarios where existing passive attacks struggle to reconstruct the client's private data effectively, SDAR consistently achieves significantly superior attack performance, even comparable to active attacks. On CIFAR-10, at the deep split level of 7, SDAR achieves private feature reconstruction with less than 0.025 mean squared error in both the vanilla and the U-shaped SL, and attains a label inference accuracy of over 98% in the U-shaped setting, while existing attacks fail to produce non-trivial results.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. BettiSplit: Topology-Guided Privacy-Aware Split Learning Against Feature Inversion and Gradient Leakage

    cs.LG 2026-07 conditional novelty 6.0 of 10

    Persistent Betti-1 of smashed activations is proposed as an attack-free indicator of feature-inversion risk in split learning, used for split selection and regularization.

  2. SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split Learning (Full Version)

    cs.CR 2025-01 conditional novelty 6.0 of 10

    SafeSplit detects poisoned client updates in U-shaped split learning by comparing DCT frequency distances and rotational distances of backbone states, then rolling back to the latest benign checkpoint; experiments sho...

  3. How Breakable Is Privacy: Probing and Resisting Model Inversion Attacks in Collaborative Inference

    cs.CR 2025-01 conditional novelty 5.0 of 10

    A mutual-information-based criterion, Dmia, predicts model inversion attack difficulty in collaborative inference, and the SiftFunnel defense suppresses the criterion's factors to raise reconstruction error with only ...

Pith tools