Presentation
Ensembler: Protect Collaborative Inference Privacy from Model Inversion Attack via Selective Ensemble
DescriptionDuring collaborative inference with a cloud, it is sometimes essential for the client to shield its sensitive information. In this paper, we introduce Ensembler, an extensible framework designed to substantially increase the difficulty of conducting model inversion attacks for adversarial parties. Ensembler leverages selective model ensemble on the adversarial server to obfuscate its reconstruction. Our experiments demonstrate that Ensembler can effectively shield images from reconstruction attacks when the client keeps even just one layer, significantly outperforming baseline methods by up to 43.5% in structural similarity. At the same time, Ensembler only incurs 4.8% overhead during inference time.
Event Type
Research Manuscript
TimeTuesday, June 2411:30am - 11:45am PDT
Location3006, Level 3


