Abstract
This paper investigates the privacy risks associated with Split Inference (SI), a collaborative deep learning paradigm that can distribute deep neural networks and corresponding inference tasks to both clients and servers. Previous research has shown that server-side adversaries, who are unable to query target model, can use membership inference attacks to compromise the privacy of training data in the model deployed in SI systems. However, this attack scheme relies on querying the target sample directly to the shadow model, which may result in unsatisfactory performance due to poor alignment. To address this limitation, we explore the possibility of Knowledge Transfer through the server model in SI, specifically, by splicing a pseudo-client model to train a reconstructed model that can inherit the memory knowledge of the training data of the original model. This procedure reveals the inherent privacy leakage of SI. Based on this insight, we propose a practical attack strategy called Knowledge Transfer Membership Inference Attack (KTMIA), targeting query-free server-side adversaries in SI. We implement KTMIA on several benchmark datasets and models, and comprehensive experiments demonstrate that our method can achieve superior performance in terms of different metrics even under realistic and worst-case query-free conditions.
| Original language | English |
|---|---|
| Article number | 132247 |
| Journal | Neurocomputing |
| Volume | 666 |
| DOIs | |
| State | Published - Feb 14 2026 |
Keywords
- Knowledge transfer
- Membership inference attack
- Split inference
Fingerprint
Dive into the research topics of 'Membership inference attacks against split inference via knowledge transfer'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver