Search arXivSearch

arXiv · 2506.15412

Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference

Abstract

In collaborative inference (CI), transmitting intermediate representations $Z$ from edge devices enables model inversion attacks (MIA) that reconstruct the original inputs $X$, while existing defenses mainly perturb shallow-layer $Z$ at the cost of utility. We instead ask where an edge-cloud model should be partitioned to obtain intrinsic resistance to MIA. We challenge the intuition that depth is the driver of MIA resistance, and show that depth is sufficient only insofar as it enables a representational transition; this transition is necessary for intrinsic resistance and is marked by an abrupt rise in the lower bound of $H(X|Z)$. Correspondingly, the decisive variance term in the entropy bound shifts from a global variance to the intra-class mean-squared radius $R_c^2$ rather than dimensionality alone, yielding an $R_c^2$-based criterion to locate the transition zone, or identify it post hoc from MIA outcomes, which we term the Golden Partition Zone (GPZ). We further explain how $R_c^2$ evolves during training and show that it can be controlled through the label distribution; we refer to this controllable dynamic behavior as the Neural Vortex, an analysis-backed explanatory concept. Across four representative deep vision models, partitioning at the GPZ yields more than 4x higher reconstruction MSE compared to shallow splits; under entropy and inversion-model enhancements, decision-level representations provide 66 percent stronger resistance than feature-level ones, and we further observe that data type affects both the transition boundary and reconstruction.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Rongke Liu, Youwen Zhu, Lei Zhou, Xianglong Zhang, Dong Wang. 2026-05-20. Partitioning for Intrinsic Model Inversion Resistance in Collaborative Inference. https://arxiv.org/abs/2506.15412

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

Radiance-Field Guided Pretraining: Scaling Localization Models with Unlabeled Wireless Signals

Radio frequency (RF)-based indoor localization offers significant promise for applications such as indoor navigation, augmented reality, and pervasive computing. While deep learning has greatly enhanced localization accuracy and robustness, existing localization models still face major challenges in cross-scene generalization due to their reliance on scene-specific labeled data. To address this, we introduce Radiance-Field Reinforced Pretraining (RFRP). This novel self-supervised pretraining framework couples a large localization model (LM) with a neural radio-frequency radiance field (RF-NeRF) in an asymmetrical autoencoder architecture. In this design, the LM encodes received RF spectra into latent, position-relevant representations, while the RF-NeRF decodes them to reconstruct the original spectra. This alignment between input and output enables effective representation learning using large-scale, unlabeled RF data, which can be collected continuously with minimal effort. To this end, we collected RF samples at 7,327,321 positions across 100 diverse scenes using four common wireless technologies--RFID, BLE, WiFi, and IIoT. Data from 75 scenes were used for training, and the remaining 25 for evaluation. Experimental results show that the RFRP-pretrained LM reduces localization error by over 40% compared to non-pretrained models and by 21% compared to those pretrained using supervised learning.

cs.IT

Uniform Recovery of Structured Signals from Nonlinear Observations: Improved Error Rates

Consider the recovery of structured signals from nonlinear observations. Under Gaussian matrix and a large class of unknown nonlinear link functions, Plan and Vershynin (2016) showed that generalized Lasso achieves accurate nonuniform recovery of a fixed signal. More recently, Genzel and Stollenwerk (2023) showed that generalized Lasso is indeed capable of accurately recovering all structured signals. However, in some canonical settings with discontinuous link functions, their uniform recovery error rate is essentially slower than the nonuniform one. Specifically, in the recovery of $n$-dimensional $k$-sparse vectors from $m$ measurements, generalized Lasso with a perfectly tuned $\ell_1$ constraint achieves nonuniform error rate $ O(\sqrt{k\log(en/k)/m})$, while the uniform error rate of Genzel and Stollenwerk is no faster than $O((k\log(en/k)/m)^{1/4})$. In this paper, we narrow this gap by establishing improved uniform recovery guarantees under piecewise Lipschitz link functions with well-separated jump discontinuities. We analyze a projected gradient descent (PGD) algorithm whose projection can be onto a convex set or a cone, and our results for the PGD with a convex set are also valid for the generalized Lasso. In sparse recovery, the improved uniform error rates match the nonuniform rate $O(\sqrt{k\log(en/k)/m})$ up to logarithmic factors. Under the sign link function, we further show that iterative hard thresholding (a specific instance of the PGD) achieves uniform recovery error rate $O(\sqrt{k\log(en/k)/m})$, matching the nonuniform rate up to a universal constant. Technically, the uniform guarantees for the PGD are obtained by showing that the gradient maps satisfy the restricted approximate invertibility condition uniformly over all signals. We demonstrate that this is a general approach to uniform recovery under nonlinear observations.

cs.IT

Enhanced Feedback Mechanisms for Resource-Efficient Incremental Redundancy

Incremental redundancy (IR) can reduce error rates by spreading coded bits across multiple transmission attempts. However, conventional stop-and-wait operation with coarse feedback often over-provisions retransmissions, triggers unnecessary decoding attempts, and increases end-to-end latency. This paper develops enhanced feedback and scheduling mechanisms that predict the additional redundancy needed for successful decoding and allocate only the required resources. We study two complementary strategies. First, using channel statistics, we learn a one- or two-shot mapping from channel quality to the minimum redundancy budget. As a byproduct, we derive an achievable reliability lower bound on the error probability of hybrid automatic repeat request (HARQ) systems. Numerical results with polar-coded IR-HARQ scheme show that the bound can be closely approached by appropriately selecting the second-transmission redundancy over a wide SNR range with savings up to 60\% in retransmission size. Second, we propose a realization-aware early-feedback mechanism that uses first-transmission reliability information to make per-codeword decisions before decoding: whether the codeword is already decodable, if not, how many additional redundancy versions are needed, or whether decoding is unlikely and rate adaptation is preferable. Link-level simulations with 5G NR LDPC codes show that both predictors achieve high accuracy (about 96\% in our study), increasing the probability of successful decoding within at most two transmission occasions.

cs.IT