科研速览 · Science Skim继续刷下去 · Keep skimming →
◆ IEEE Internet of Things Journal2026-05-15· Computer science

Defending Against Model Inversion Attacks for Biomedical Images via Learnable Data Perturbation

Shiyi Jiang, Farshad Firouzi, Krishnendu Chakrabarty

原始摘要(英文原文)· Original abstract
The increasing need for sharing healthcare data and collaborating on clinical research has raised privacy concerns. Health information leakage due to malicious attacks can lead to serious problems such as misdiagnoses and patient identification issues. Privacy-preserving machine learning (PPML) and privacy-enhancing technologies, particularly federated learning (FL), have emerged in recent years as innovative solutions to balance privacy protection with data utility; however, they also suffer from inherent privacy vulnerabilities. Model inversion attacks constitute major threats to data sharing in federated learning. Researchers have proposed many defenses against model inversion attacks. However, current defense methods for healthcare data lack generalizability, i.e., existing solutions may not be applicable to data from a broader range of populations. In addition, most existing defense methods are tested using non-healthcare data, which raises concerns about their applicability to real-world healthcare systems. In this study, we present a defense against model inversion attacks in federated learning. We achieve this using latent data perturbation and minimax optimization, utilizing both general and medical image datasets. We compare our method against two baselines and observe a reduction of at least 4% in the attacker’s accuracy when classifying reconstructed images, while maintaining model utility within a 1.5% drop of client classification accuracy of the undefended model. These results demonstrate improved privacy protection with minimal utility loss and suggest the potential for a generalizable defense in healthcare settings.
读原文 · Read the paper ↗

AI 追问PRO

登录后使用 AI 追问

讨论区

登录后参与讨论

相关论文 · Related

Defending Against Model Inversion Attacks for Biomedical Images via Learnable Data Perturbation — 科研速览 Science Skim