2501.00824
A study of privacy leakage in collaborative inference, where a neural network is split so an edge device computes intermediate features that a cloud model completes, and an adversary running a model …
A quantitative criterion for how easily an adversary can reconstruct a private input from the intermediate features an edge device transmits to a cloud model, expressed through mutual information, conditional and feature entropy, and the amount of effective (non-redundant) information in the features. The same criterion guides SiftFunnel, a lightweight funnel-shaped edge network that suppresses invertible redundant information with linear and nonlinear correlation constraints and label smoothing, resisting reconstruction while preserving task accuracy.
A study of privacy leakage in collaborative inference, where a neural network is split so an edge device computes intermediate features that a cloud model completes, and an adversary running a model …