Model inversion defense method and device based on compression fine tuning and medium
By adopting a compression fine-tuning method in model inversion defense, pre-training using public data sets and introducing external compression networks, the impact of model inversion defense on the performance of main task and the training cost is solved, and the effect of effectively resisting model inversion attacks is achieved.
Patent Information
- Application Number
- CN202510712656.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2045-05-30
AI Technical Summary
Current model inversion defense has problems such as large impact on main task performance and high training cost, and it is difficult to withstand advanced model inversion attacks.
A model inversion defense method based on compression fine-tuning is adopted. By pre-training the model on a large-scale public data set and introducing an external compression network, it only uses private data to fine-tune a small amount of parameters after dimension compression, so as to confuse a small amount of private information with a large amount of public information, hindering attackers from stealing the private data used for training.
It effectively reduces the success rate of model inversion attacks, protects the security of private data, and does not introduce additional model inference overhead, maintains the performance and efficiency of the model on the main task.
Smart Images

Figure CN120234802A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of model inversion defense, and in particular, to a model inversion defense method, device, and medium based on compressed fine-tuning. Background Art
[0002] In recent years, deep learning technology has developed rapidly and has been widely applied to production and life practices. However, in the process of applying deep neural network models, a large amount of private data is often required, which leads to the fact that the model is vulnerable to privacy leakage attacks during application. That is, even if the dataset used for training does not leak itself, attackers can still use various privacy attack algorithms, such as membership inference attacks, attribute inference attacks, and model inversion attacks, to steal the private information used for model training by accessing the model. Among them, a major threat to privacy security is the model inversion attack, which allows attackers to use the output information of the artificial intelligence model in the inference stage to reconstruct the private data used to train this model.
[0003] Currently, the mainstream model inversion attack method is the generative model inversion attack. The attacker trains an image generator using a public dataset that is relatively close to the distribution of private data to capture the structural features related to the private data. During the attack, the attacker first samples latent vectors in the input space of this generator, generates corresponding images through the generator, accesses the model with these images, obtains the output of the model, and gets the classification loss. At the same time, combined with the attacker's own understanding of the private data, the prior loss is obtained, and the two losses jointly guide the optimization of the input latent vectors. Eventually, the optimized latent vectors generate pictures through the generator that have a large number of similar features to the private pictures.
[0004] In recent years, model inversion attacks have been mainly optimized within this framework, and have achieved extremely high attack success rates, posing a great threat to private data. To resist the privacy security threat of model inversion attacks, several model inversion defense schemes have been proposed in recent years. However, the current model inversion defense algorithms need to make a large compromise on the performance of the model in the main task, and can no longer resist advanced model inversion attack algorithms. The main deficiencies of existing model inversion defense research in resisting model inversion attacks are as follows: (1) Need to make a large compromise on the performance of the model in the main task: To achieve a better model inversion defense effect, existing defense methods will reduce the accuracy of the model in the main task, affecting its usability. For example, methods based on reducing mutual information and bilateral optimization will penalize the information carried in the model output, which conflicts with the main task of the model and will reduce the accuracy of the model in the main task. Methods based on introducing gradient disappearance will also cause the training process itself to suffer from the problem of gradient disappearance, affecting the training of the model itself.
[0005] (2) Increased training cost: Most of the existing defense algorithms use the method of adding a regularization term loss for defense, which will increase the time complexity of model calculation.
[0006] (3) Difficulty in resisting the state-of-the-art model inversion attack algorithms: At present, the model inversion attack technology has been continuously improved and refined, and the current defense algorithms have difficulty achieving good defense effects.
[0007] In summary, the current model inversion defense has problems such as a large impact on the main task performance and high training costs, and it has difficulty resisting advanced model inversion attacks. Therefore, there is an urgent need for a lightweight defense strategy to achieve better defense effects while not overly affecting the model performance. Summary of the Invention
[0008] Embodiments of the present invention provide a model inversion defense method, device, and medium based on compression fine-tuning to solve the following technical problems: The current model inversion defense has problems such as a large impact on the main task performance and high training costs, and it has difficulty resisting advanced model inversion attacks.
[0009] Embodiments of the present invention adopt the following technical solutions: On the one hand, embodiments of the present invention provide a model inversion defense method based on compression fine-tuning. The method includes: pre-training a model to be trained through a public dataset to obtain a pre-trained model and corresponding first model weight parameters; Constructing an external compression network for each network layer of the pre-trained model; wherein, the network layer includes a linear layer and / or a convolutional layer; Fine-tuning the parameters of the external compression network through a privacy dataset to obtain second model weight parameters; Mixing the first model weight parameters corresponding to each network layer with the second model weight parameters to obtain mixed model weight parameters, and applying them to the pre-trained model to obtain an optimized model.
[0010] In a feasible embodiment, pre-training the model to be trained through a public dataset to obtain a pre-trained model and corresponding first model weight parameters specifically includes: Obtaining the public dataset required for the model to be trained on the network and performing adaptive preprocessing on the public dataset to make it meet the training requirements of the model to be trained; Pre-training the model to be trained through the preprocessed public dataset to obtain a pre-trained model; Obtaining the weight parameters of each network layer in the pre-trained model to form the first model weight parameters; wherein, the weight parameters encode public information related to the public dataset.
[0011] In a feasible implementation, an external compression network is constructed for each network layer of the pre-trained model, specifically including: A compression layer and a restoration layer are respectively introduced in parallel to each network layer of the pre-trained model to form the external compression network; wherein, the output end of the compression layer is connected to the output end of the restoration layer.
[0012] In a feasible implementation, the external compression network is fine-tuned through a privacy dataset to obtain second model weight parameters, specifically including: While keeping the first model weight parameters of the network layers in the pre-trained model unchanged, the external compression network is trained through the privacy dataset; During the training process, the input features are compressed and dimension-reduced by the compression layer and then the model parameters are trained, and the trained parameter dimensions are restored to the original output dimensions of the network layer by the restoration layer to obtain the second model weight parameters; wherein, the number of parameters of the second model weight parameters is much smaller than the number of parameters of the first model weight parameters.
[0013] In a feasible implementation, the input features are compressed and dimension-reduced by the compression layer, and the compressed dimensions are restored to the initial dimensions by the restoration layer to fine-tune the parameters of the external compression network, specifically including: If the current network layer is a linear layer, let the input dimension of the linear layer be , and the output dimension be , then the weight of the linear layer of the pre-trained model can be obtained as , which contains weight parameters; Through the compression layer in the external compression network of the linear layer, the input features during the training process are compressed from dimensions to r dimensions, and the weight of the compression layer can be obtained as , which contains weight parameters; wherein, r is much smaller than and ; Through the restoration layer, the output features of the compression layer are restored from r dimensions to dimensions, and the weight of the restoration layer can be obtained as , which contains weight parameters; Finally, the total number of weight parameters of the fine-tuned external compression network of the linear layer is , which is much smaller than the weight parameters of the original linear layer.
[0014] In a feasible implementation, the input features are compressed and dimension-reduced by the compression layer, and the compressed dimension is restored to the initial dimension by the restoration layer to fine-tune the parameters of the external compression network. Specifically, it further includes: If the current network layer is a convolutional layer, let the number of input channels of the convolutional layer of the pre-trained model be , and the number of output channels be , and the convolutional kernel size be . Then, the weights of the convolutional layer of the pre-trained model are , including weight parameters; Through the compression layer in the external compression network of the convolutional layer, the number of input channels during the training process is compressed from to t . Then, the weights of the compression layer are , including weight parameters; where t is much smaller than and ; Through the restoration layer, the number of output channels of the compression layer is restored from t to . Then, the weights of the restoration layer are , including weight parameters; Finally, the fine-tuned external compression network of the convolutional layer has a total of weight parameters, which is much smaller than the weight parameters of the original convolutional layer.
[0015] In a feasible implementation, the first model weight parameters and the second model weight parameters of each network layer are mixed to obtain mixed model weight parameters. Specifically, it includes: When the network layer is a linear layer, according to , the first model weight parameters and the second model weight parameters of the linear layer are mixed to obtain mixed model weight parameters ; Among them, is the first model weight parameter of the linear layer, is the restoration layer weight in the second model weight parameters, and is the compression layer weight in the second model weight parameters.
[0016] In a feasible implementation, the first model weight parameters and the second model weight parameters of each network layer are mixed to obtain mixed model weight parameters. Specifically, it includes: When the network layer is a convolutional layer, according to , mix the first model weight parameters of the convolutional layer with the second model weight parameters to obtain the mixed model weight parameters ; Among them, the convolutional kernel size of the convolutional layer is , ; is the first model weight parameter of the convolutional layer, is the weight of the restoration layer in the second model weight parameter, is the weight of the compression layer in the second model weight parameter.
[0017] On the other hand, an embodiment of the present invention further provides a model inversion defense device based on compression fine-tuning. The device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, so that the at least one processor can execute the model inversion defense method based on compression fine-tuning as described above.
[0018] Finally, an embodiment of the present invention further provides a storage medium. The storage medium is a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores at least one program. Each program includes instructions. When the instructions are executed by a terminal, the terminal executes the model inversion defense method based on compression fine-tuning as described above.
[0019] Compared with the prior art, a model inversion defense method, device and medium based on compression fine-tuning provided by an embodiment of the present invention have the following beneficial effects: The present invention uses lightweight compression fine-tuning operations for model inversion defense. By pre-training the model on a large-scale public dataset and introducing an external compression network, only a small number of parameters after dimension compression are fine-tuned using private data, realizing the confusion of a small amount of private information with a large amount of public information, hindering attackers from stealing private data used for training, and thus protecting the security of private data.
[0020] In the present invention, the model compresses the input features of private data to a lower dimension, which means that the model can only capture a small number of features that are crucial for the main task, while discarding the remaining redundant information, thereby reducing the model information that can be obtained by the attacker. From the above analysis, it can be seen that the number of parameters fine-tuned using private data is much smaller than the number of parameters of the original model. This makes the proportion of private data encoded in the model parameters relatively small, hidden in the parameters of a large number of encoded public data, thereby reducing the risk of privacy leakage. And the number of parameters of the model after the two parts of parameters are combined is the same as that of the original model. Therefore, the present invention does not introduce additional model inference overhead.
[0021] The technical solution provided by the present invention can be applied to the privacy protection of various recognition systems, such as face recognition, speech recognition, palmprint recognition, etc. An attacker of a model inversion attack can reconstruct the privacy information such as the face, voice, and palmprint of the corresponding individual by continuously accessing the model, causing significant privacy and security risks. Applying the model inversion defense technology of the present invention can effectively reduce the risk of such privacy leakage, improve the security of privacy data, and has high practical value. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings. In the drawings: Figure 1 It is a flowchart of a model inversion defense method based on compression and fine-tuning provided by an embodiment of the present invention; Figure 2 It is a schematic diagram of a model inversion defense architecture based on compression and fine-tuning provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of the structure of an externally connected compression network provided by an embodiment of the present invention; Figure 4 It is a schematic diagram of the structure of a model inversion defense device based on compression and fine-tuning provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0023] In order to enable those skilled in the art to better understand the technical solutions in the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0024] An embodiment of the present invention provides a model inversion defense method based on compression and fine-tuning, as Figure 1 shown, the model inversion defense method based on compression and fine-tuning specifically includes steps S101 - S104: S101. Pre-train the model to be trained through a public data set to obtain a pre-trained model and corresponding first model weight parameters.
[0025] Specifically, first obtain the public data set required for the model to be trained on the network, and perform adaptive preprocessing on the public data set to make it meet the training requirements of the model to be trained.
[0026] Further, the training process of the entire model is divided into three stages. Figure 2 It is a schematic diagram of a model inversion defense architecture based on compression and fine-tuning provided by an embodiment of the present invention. As Figure 2 shown, the process of the first stage is as follows: Through the preprocessed public dataset, the model to be trained is pre-trained to obtain a pre-trained model. Then, the weight parameters of each network layer in the pre-trained model are obtained to form the first model weight parameters.
[0027] During model training, the data used to train the model will be implicitly embedded in the parameters of the model. The attacker of the model inversion attack takes advantage of this feature to reconstruct the training data. Therefore, in order to resist the model inversion attack, the present invention aims to reduce the number of parameters encoding private data information in the model. To enable the model to still exhibit efficient performance, the present invention first uses a large-scale public dataset for pre-training, so that the model itself has good feature extraction capabilities. At the same time, since the public dataset is used for training, the parameters of the pre-trained model encode public information, and the attacker can only extract the information of the public data from it, without posing a threat of leakage to the security of the private data.
[0028] S102. Construct an external compression network for each network layer of the pre-trained model; wherein, the network layer includes a linear layer and / or a convolutional layer.
[0029] Specifically, a compression layer and a restoration layer are respectively introduced in parallel to each network layer of the pre-trained model to form an external compression network.
[0030] As a feasible implementation manner, Figure 3 It is a schematic diagram of the structure of an external compression network provided by an embodiment of the present invention. As Figure 3 shown, for each linear layer and / or convolutional layer, fine-tuning is performed in the way of an external component. During the fine-tuning process, the weights of the first-stage pre-training are kept unchanged, and a compression layer and a restoration layer are introduced in parallel to the linear layer or convolutional layer. The output end of the compression layer is connected to the output end of the restoration layer. The compression layer is responsible for reducing the input features to a smaller dimension, and the restoration layer is responsible for restoring the compressed dimension back to the dimension to be output. During the fine-tuning process using private data in the second stage, only the parameters of this compression layer and restoration layer are fine-tuned.
[0031] S103. Fine-tune the parameters of the external compression network through the private dataset to obtain the second model weight parameters.
[0032] Specifically, while keeping the first model weight parameters of the network layers in the pre-trained model unchanged, the external compression network is trained through the private dataset.
[0033] During the training process, the input features are compressed and dimension-reduced by a compression layer, and then the model parameters are trained. The dimension of the trained parameters is restored to the original output dimension of the network layer by a restoration layer to obtain the second model weight parameters. Among them, the number of parameters of the second model weight parameters is much smaller than that of the first model weight parameters.
[0034] As a feasible implementation, if the current network layer is a linear layer, let the input dimension of the linear layer be , and the output dimension be . The weight of the linear layer of the pre-trained model can be obtained as , which contains weight parameters.
[0035] By connecting the compression layer in the compression network to the linear layer, the input features during the training process are compressed from dimensions to r dimensions. The weight of the compression layer can be obtained as , which contains weight parameters. Among them, r is much smaller than and , and and are both greater than 2.
[0036] Furthermore, the output features of the compression layer are restored from r dimensions to dimensions by the restoration layer. The weight of the restoration layer can be obtained as , which contains weight parameters. The total number of weight parameters of the fine-tuned linear layer connected to the compression network finally obtained is , which is much smaller than the weight parameters of the original linear layer.
[0037] As another feasible implementation, if the current network layer is a convolutional layer, let the number of input channels of the convolutional layer of the pre-trained model be , the number of output channels be , and the convolutional kernel size be . The weight of the convolutional layer of the pre-trained model can be obtained as , which contains weight parameters.
[0038] By connecting the compression layer in the compression network to the convolutional layer, the number of input channels during the training process is compressed from to t . The weight of the compression layer can be obtained as , which contains weight parameters. Among them, t is much smaller than and , and and are both greater than 2.
[0039] Furthermore, the output channel number of the compression layer is restored from t to through the restoration layer, and the restoration layer weights can be obtained as , including weight parameters. The final fine-tuned convolutional layer with an external compression network has weight parameters, which is much smaller than the weight parameters of the original convolutional layer.
[0040] The above operations can effectively reduce the privacy information that the model can leak for the following reasons: 1. The model compresses the input features of the privacy data into a lower dimension, which means that the model can only capture a small number of features that are crucial for the main task and discard the remaining redundant information, thereby reducing the model information that can be obtained by the attacker.
[0041] 2. The number of parameters fine-tuned using the privacy data is much smaller than the number of parameters of the original model. This makes the proportion of the privacy data encoded in the model parameters relatively small and hidden among the parameters encoding a large amount of public data, thereby reducing the risk of privacy leakage.
[0042] S104. Mix the first model weight parameters corresponding to each network layer with the second model weight parameters to obtain the mixed model weight parameters, and apply them to the pre-trained model to obtain the optimized model.
[0043] Specifically, as Figure 2 shown, in the third stage of model training, the compression layer weight parameters and the restoration layer weight parameters are merged into the pre-trained weight parameters, so that the pre-trained weight parameters encoding public information and the model fine-tuning parameters encoding privacy information are mixed and confused with each other, without affecting the result of model inference and keeping the inference speed unchanged. The specific mixing principle formula is: mixed weight parameter = first model weight parameter value + compression layer weight parameter value × restoration layer weight parameter value. The number of parameters of the model mixed by this method is the same as that of the original model. Therefore, the present invention does not introduce additional inference overhead.
[0044] As a feasible implementation, when the network layer is a linear layer, according to , the first model weight parameters of the linear layer are mixed with the second model weight parameters to obtain the mixed model weight parameters . Among them, is the first model weight parameter of the linear layer, is the restoration layer weight in the second model weight parameters, and is the compression layer weight in the second model weight parameters.
[0045] As a feasible implementation, when the network layer is a convolutional layer, according to , the first model weight parameters of the convolutional layer are mixed with the second model weight parameters to obtain mixed model weight parameters . Among them, the convolutional kernel size of the convolutional layer is , ; is the first model weight parameter of the convolutional layer, is the weight of the restoration layer in the second model weight parameter, is the weight of the compression layer in the second model weight parameter. Among them, ":" represents a custom weight value, which is only a representative symbol, and its specific meaning has no impact on this solution, so it will not be elaborated here.
[0046] In addition, an embodiment of the present invention also provides a model inversion defense device based on compression fine-tuning, as Figure 4 shown, the model inversion defense device based on compression fine-tuning specifically includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, so that the at least one processor can execute: Pre-train the model to be trained through a public dataset to obtain a pre-trained model and corresponding first model weight parameters; Construct an external compression network for each network layer of the pre-trained model; wherein, the network layer includes a linear layer and / or a convolutional layer; Fine-tune the parameters of the external compression network through a private dataset to obtain second model weight parameters; Mix the first model weight parameters corresponding to each network layer with the second model weight parameters to obtain mixed model weight parameters, and apply them to the pre-trained model to obtain an optimized model.
[0047] Finally, the present invention also provides a storage medium, the storage medium is a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium stores at least one program, each program includes instructions, and when the instructions are executed by a terminal, the terminal is made to execute: Pre-train the model to be trained through a public dataset to obtain a pre-trained model and corresponding first model weight parameters; Construct an external compression network for each network layer of the pre-trained model; wherein, the network layer includes a linear layer and / or a convolutional layer; Fine-tune the parameters of the external compression network through a private dataset to obtain second model weight parameters; Mix the first model weight parameters corresponding to each network layer with the second model weight parameters to obtain mixed model weight parameters, and apply them to the pre-trained model to obtain an optimized model.
[0048] Each embodiment in the present invention is described in a progressive manner. For the same or similar parts among the embodiments, reference can be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the embodiments of the device, equipment, and non-volatile computer storage medium, since they are basically similar to the method embodiments, the description is relatively simple, and reference can be made to the corresponding parts of the method embodiments for the relevant content.
[0049] The above describes specific embodiments of the present invention. Additionally, the processes depicted in the figures do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0050] The above are only the embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, various changes and modifications can be made to the embodiments of the present invention. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the embodiments of the present invention shall be included within the protection scope of the present invention.
Claims
1. A model inversion defense method based on compressed fine-tuning, characterized in that The method includes: Pre-training the model to be trained through a public dataset to obtain a pre-trained model and corresponding first model weight parameters; Constructing an external compression network for each network layer of the pre-trained model; wherein, the network layer includes a linear layer and / or a convolutional layer; Fine-tuning the parameters of the external compression network through a private dataset to obtain second model weight parameters; Mixing the first model weight parameters corresponding to each network layer with the second model weight parameters to obtain mixed model weight parameters, and applying them to the pre-trained model to obtain an optimized model.
2. The model inversion defense method based on compression and fine-tuning according to claim 1, characterized in that Pre-training the model to be trained through a public dataset to obtain a pre-trained model and corresponding first model weight parameters, specifically including: Obtaining the public dataset required by the model to be trained on the network and performing adaptive preprocessing on the public dataset to make it meet the training requirements of the model to be trained; Pre-training the model to be trained through the preprocessed public dataset to obtain a pre-trained model; Obtaining the weight parameters of each network layer in the pre-trained model to form the first model weight parameters; wherein, the weight parameters encode public information related to the public dataset.
3. The model inversion defense method based on compression and fine-tuning according to claim 1, characterized in that Constructing an external compression network for each network layer of the pre-trained model, specifically including: Introducing a compression layer and a restoration layer respectively in the bypass of each network layer of the pre-trained model to form the external compression network; wherein, the output end of the compression layer is connected to the output end of the restoration layer.
4. A model inversion defense method based on compression and fine-tuning according to claim 3, characterized in that, Fine-tuning the parameters of the external compression network through a private dataset to obtain second model weight parameters, specifically including: Training the external compression network through the private dataset while keeping the first model weight parameters of the network layers in the pre-trained model unchanged; During the training process, compressing and reducing the dimension of the input features through the compression layer and then training the model parameters, and restoring the dimension of the trained parameters to the original output dimension of the network layer through the restoration layer to obtain the second model weight parameters; wherein, the number of parameters of the second model weight parameters is much smaller than the number of parameters of the first model weight parameters.
5. The model inversion defense method based on compression and fine-tuning according to claim 4, characterized in that, Compressing and reducing the dimension of the input features through the compression layer and restoring the compressed dimension to the initial dimension to fine-tune the parameters of the external compression network, specifically including: If the current network layer is a linear layer, set the input dimension of the linear layer to be , and the output dimension to be . Then, the weights of the linear layer of the pre-trained model can be obtained as , which contains weight parameters. By connecting the compression layer in the compression network through a linear layer, the input features during the training process are compressed from dimensions to r dimensions. The weights of the compression layer can be obtained as , which contain weight parameters. Among them, r is much smaller than and . The output features of the compression layer are restored from r dimensions to dimensions through the restoration layer, and the weights of the restoration layer are , including weight parameters; The finally obtained fine-tuned linear layer circumscribed compression network has a total of weight parameters, which is much less than the weight parameters of the original linear layer.
6. A model inversion defense method based on compression and fine-tuning according to claim 4, characterized in that, Compressing and reducing the dimension of the input features through the compression layer and restoring the compressed dimension to the initial dimension to fine-tune the parameters of the external compression network, specifically further including: If the current network layer is a convolutional layer, set the number of input channels of the convolutional layer of the pre-trained model to , the number of output channels to , and the convolutional kernel size to . Then, the weights of the convolutional layer of the pre-trained model are , which contain weight parameters; By connecting the compression layer in the compression network outside the convolutional layer, the number of input channels during the training process is reduced from to t . The weight of the compression layer can be obtained as , which contains weight parameters. Among them,[[]] t is much smaller than and . Reducing the number of output channels of the compression layer from t to through the restoration layer, the weight of the restoration layer can be obtained as , including weight parameters; The finally obtained fine-tuned convolutional layer circumscribed compression network has a total of weight parameters, which is much less than the weight parameters of the original convolutional layer.
7. A model inversion defense method based on compression and fine-tuning according to claim 1, characterized in that Mixing the first model weight parameters of each network layer with the second model weight parameters to obtain mixed model weight parameters, specifically including: When the network layer is a linear layer, according to , the first model weight parameter and the second model weight parameter of the linear layer are mixed to obtain a mixed model weight parameter ; Among them, is the first model weight parameter of the linear layer, is the weight of the restoration layer in the second model weight parameter, is the weight of the compression layer in the second model weight parameter.
8. A model inversion defense method based on compression and fine-tuning according to claim 7, characterized in that, Mixing the first model weight parameters of each network layer with the second model weight parameters to obtain mixed model weight parameters, specifically including: When the network layer is a convolutional layer, according to , the first model weight parameter and the second model weight parameter of the convolutional layer are mixed to obtain a mixed model weight parameter ; Among them, the convolution kernel size of the convolutional layer is , ; is the first model weight parameter of the convolutional layer, is the weight of the restoration layer in the second model weight parameter, is the weight of the compression layer in the second model weight parameter.
9. A model inversion defense device based on compressed fine-tuning, characterized in that, The device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, so that the at least one processor can execute a model inversion defense method based on compressed fine-tuning according to any one of claims 1-8.
10. A storage medium, characterized in that, The storage medium is a non-volatile computer-readable storage medium, and the non-volatile computer-readable storage medium stores at least one program. Each program includes instructions that, when executed by a terminal, cause the terminal to execute a model inversion defense method based on compressed fine-tuning according to any one of claims 1-8.
Citation Information
Patent Citations
Deep neural network model inversion attack defense method and device
CN115719085A
Model compression method and device, equipment and storage medium
CN117408302A
Differential privacy-based self-supervised low-rank decomposition medical image privacy protection method and system
CN117671352A
Text data processing method and device, computer equipment, readable storage medium and program product
CN120012770A
Layer-Wise Distillation for Protecting Pre-Trained Neural Network Models
US20200311540A1