NoPeek: Information leakage reduction to share activations in distributed deep learning
About
For distributed machine learning with sensitive data, we demonstrate how minimizing distance correlation between raw data and intermediary representations reduces leakage of sensitive raw data patterns across client communications while maintaining model accuracy. Leakage (measured using distance correlation between input and intermediate representations) is the risk associated with the invertibility of raw data from intermediary representations. This can prevent client entities that hold sensitive data from using distributed deep learning services. We demonstrate that our method is resilient to such reconstruction attacks and is based on reduction of distance correlation between raw data and learned representations during training and inference with image datasets. We prevent such reconstruction of raw data while maintaining information required to sustain good classification accuracies.
Related benchmarks
| Task | Dataset | Result | Rank | |
|---|---|---|---|---|
| Prompt inversion attack defense | Skytrax | Attack Accuracy81.7 | 22 | |
| Medical Image Classification | ChestMNIST | -- | 22 | |
| Model Inversion Defense | CIFAR-100 (test) | Accuracy63.6 | 19 | |
| Privacy defense against classification attack | Legal | Attack Score92.5 | 11 | |
| Prompt inversion attack defense | medical | Attack Accuracy75.5 | 11 | |
| Prompt inversion attack defense | Legal | Attack Accuracy92.5 | 11 | |
| Privacy defense against classification attack | medical | Attack Success Rate (Atk)75.5 | 11 | |
| Privacy Evaluation | ChestMNIST | Reconstruction SSIM0.691 | 8 |