Pith. sign in

REVIEW 2 cited by

Be Careful What You Smooth For: Label Smoothing Can Be a Privacy Shield but Also a Catalyst for Model Inversion Attacks

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2310.06549 v5 pith:4Q654H2R submitted 2023-10-10 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords modelsmoothinglabelprivacymiasattacksinformationinversion
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Label smoothing -- using softened labels instead of hard ones -- is a widely adopted regularization method for deep learning, showing diverse benefits such as enhanced generalization and calibration. Its implications for preserving model privacy, however, have remained unexplored. To fill this gap, we investigate the impact of label smoothing on model inversion attacks (MIAs), which aim to generate class-representative samples by exploiting the knowledge encoded in a classifier, thereby inferring sensitive information about its training data. Through extensive analyses, we uncover that traditional label smoothing fosters MIAs, thereby increasing a model's privacy leakage. Even more, we reveal that smoothing with negative factors counters this trend, impeding the extraction of class-related information and leading to privacy preservation, beating state-of-the-art defenses. This establishes a practical and powerful novel way for enhancing model resilience against MIAs.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. How Breakable Is Privacy: Probing and Resisting Model Inversion Attacks in Collaborative Inference

    cs.CR 2025-01 conditional novelty 5.0 of 10

    A mutual-information-based criterion, Dmia, predicts model inversion attack difficulty in collaborative inference, and the SiftFunnel defense suppresses the criterion's factors to raise reconstruction error with only ...

  2. Deep Learning Model Inversion Attacks and Defenses: A Comprehensive Survey

    cs.CR 2025-01 accept novelty 4.0 of 10

    A structured literature review that taxonomizes model inversion attacks and defenses and provides a public resource repository.

Pith tools