SOPC: Controllable Privacy-Utility Trade-off via Two-Stage Feature Coding against Model Inversion Attacks
Abstract
In collaborative inference, model inversion attacks (MIAs) pose a serious threat to privacy by reconstructing private data through access to the outputs or intermediate representations of target models. Existing defenses have proposed various protection strategies based on mutual information regularization or adversarial training. However, these methods rely on loss weights to implicitly balance privacy and utility, lacking a systematic characterization of the utility-privacy Pareto frontier and its attainability. Such implicit privacy protection hence causes sharp utility degradation as privacy improves, hindering the practical deployment of these defenses in collaborative inference. Motivated by this issue, we provide a theoretical analysis of the trade-off between privacy protection and task utility, quantitatively characterizing the lower bound on accuracy degradation incurred by privacy protection. Building on the analysis, we propose a two-stage model inversion defense framework. The first stage spatially quantizes the feature into learnable prototypes, forming a hard information bottleneck; the second stage injects post-quantization Gaussian noise that smoothly adjusts the utility-privacy trade-off along the frontier. Experimental results demonstrate that our method substantially enhances privacy protection while largely retaining task utility, validating the correctness of the theoretical analysis and the effectiveness of the proposed approach.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.