Yupeng Yin

dblp:345/6288 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
1since 2021 · last 2023
0000-0001-9842-6285ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Security and privacy of machine learning · 50% Privacy and data protection · 50%

Topics — the 2 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Privacy and data protection › privacy-preserving machine learning › privacy-preserving machine learning inference
collaborative inference privacy
0.712023
Ginver: Generative Model Inversion Attacks Against Collaborative Inference · WWW 2023
Security and privacy of machine learning › privacy attack
model inversion attack
0.712023
Ginver: Generative Model Inversion Attacks Against Collaborative Inference · WWW 2023

Methods — techniques the papers use, named apart from their topics

generative model inversion · 0.7
YearPublicationVenuePosition
2023 Ginver: Generative Model Inversion Attacks Against Collaborative Inference
abstract
Deep Learning (DL) has been widely adopted in almost all domains, from threat recognition to medical diagnosis. Albeit its supreme model accuracy, DL imposes a heavy burden on devices as it incurs overwhelming system overhead to execute DL models, especially on Internet-of-Things (IoT) and edge devices. Collaborative inference is a promising approach to supporting DL models, by which the data owner (the victim) runs the first layers of the model on her local device and then a cloud provider (the adversary) runs the remaining layers of the model. Compared to offloading the entire model to the cloud, the collaborative inference approach is more data privacy-preserving as the owner’s model input is not exposed to outsiders. However, we show in this paper that the adversary can restore the victim’s model input by exploiting the output of the victim’s local model. Our attack is dubbed Ginver 1: Generative model inversion attacks against collaborative inference. Once trained, Ginver can infer the victim’s unseen model inputs without remaking the inversion attack model and thus has the generative capability. We extensively evaluate Ginver under different settings (e.g., white-box and black-box of the victim’s local model) and applications (e.g., CIFAR10 and FaceScrub datasets). The experimental results show that Ginver recovers high-quality images from the victims.
Yupeng Yin, Xianglong Zhang, Huanle Zhang, Feng Li 0002, Yue Yu 0001, Xiuzhen Cheng, Pengfei Hu 0001
WWW1