arXiv:cs.LG(机器学习,全量分类)· Rongke Liu, Youwen Zhu·· 15 小时前AI 评分38
模型量化与模型反转攻击之间的关系研究
On the Relationship between Model Quantization and Model Inversion Attacks
AI 导读
研究揭示了模型量化对模型反转攻击的影响机制:量化会改变输入与预测概率间的互信息,且4 bits下特征分布的数据依赖性差异尤为显著。基于此提出的隐私感知训练后量化方法,在ResNet-50的Palm数据集4 bits下将RL-MIA严格成功率从54%降至26%,准确率仅从99.01%降至96.55%。
正文
Abstract:Model quantization reduces the numerical precision of neural network weights and activations to lower storage and computational costs. Model inversion attacks recover or reconstruct sensitive training data or inference inputs from model outputs or intermediate features, so quantization may also alter their effectiveness. However, two questions remain unresolved: How does model quantization affect model inversion? How do data characteristics influence this relationship? To address the first, we bound quantization-induced changes in mutual information between inputs and a categorical variable defined by prediction probabilities, distinguishing informational effects from attack optimization obstacles. To address the second, we identify data-dependent changes in feature distributions and inversion outcomes, with pronounced quantization sensitivity differences at 4 bits. These insights guide a privacy-aware post-training quantization method that improves inversion resistance while recovering utility. It uses a Fisher-type task-sensitivity proxy for budget-aware bit allocation, calibrates activation ranges, and jointly optimizes weight and activation scales and weight-rounding decisions with task-recovery and geometry-retention objectives and scale and rounding regularization. Experiments cover multiple metrics, neural network architectures, and face, palmprint, and iris recognition tasks. On ResNet-50, Palm at 4 bits reduces RL-MIA's strict success from 54% to 26%, while accuracy decreases from 99.01% to 96.55% relative to FP32. Our method also supports output-level defenses: adding Stealthy Shield Defense (SSD, epsilon = 0.1) to Iris at 4.5 bits reduces BREP-MI's strict success from 63.33% to 37.33%, while accuracy decreases from 92.8% to 87.6% relative to quantization alone.
| Subjects: | Cryptography and Security (cs.CR); Information Theory (cs.IT); Machine Learning (cs.LG) |
| Cite as: | arXiv:2610.00382 [cs.CR] |
| (or arXiv:2610.00382v1 [cs.CR] for this version) | |
| https://doi.org/10.48550/arXiv.2610.00382 arXiv-issued DOI via DataCite (pending registration) |
Submission history
From: Rongke Liu [view email]
[v1]
Wed, 30 Sep 2026 09:17:13 UTC (9,132 KB)
来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org