On the Relationship between Model Quantization and Model Inversion Attacks

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the unclear mechanisms by which model quantization affects inversion attacks and its ambiguous relationship with data characteristics. For the first time, it decouples the information effects of quantization from optimization barriers, establishing a data-dependent sensitivity analysis framework. We propose a privacy-aware post-training quantization method that leverages Fisher sensitivity as a surrogate to optimize bit-width allocation, integrating activation calibration, weight rounding, and geometry-preserving regularization to jointly optimize security and utility. Experimental results demonstrate that under 4-bit quantization, ResNet-50 reduces the attack success rate to 26% with negligible accuracy degradation. Furthermore, combining this approach with SSD-based defenses suppresses the success rate to 37.33%.
📝 Abstract
Model quantization reduces the numerical precision of neural network weights and activations to lower storage and computational costs. Model inversion attacks recover or reconstruct sensitive training data or inference inputs from model outputs or intermediate features, so quantization may also alter their effectiveness. However, two questions remain unresolved: How does model quantization affect model inversion? How do data characteristics influence this relationship? To address the first, we bound quantization-induced changes in mutual information between inputs and a categorical variable defined by prediction probabilities, distinguishing informational effects from attack optimization obstacles. To address the second, we identify data-dependent changes in feature distributions and inversion outcomes, with pronounced quantization sensitivity differences at 4 bits. These insights guide a privacy-aware post-training quantization method that improves inversion resistance while recovering utility. It uses a Fisher-type task-sensitivity proxy for budget-aware bit allocation, calibrates activation ranges, and jointly optimizes weight and activation scales and weight-rounding decisions with task-recovery and geometry-retention objectives and scale and rounding regularization. Experiments cover multiple metrics, neural network architectures, and face, palmprint, and iris recognition tasks. On ResNet-50, Palm at 4 bits reduces RL-MIA's strict success from 54% to 26%, while accuracy decreases from 99.01% to 96.55% relative to FP32. Our method also supports output-level defenses: adding Stealthy Shield Defense (SSD, epsilon = 0.1) to Iris at 4.5 bits reduces BREP-MI's strict success from 63.33% to 37.33%, while accuracy decreases from 92.8% to 87.6% relative to quantization alone.
Problem

Research questions and friction points this paper is trying to address.

Model Quantization
Model Inversion Attacks
Mutual Information
Privacy
Data Characteristics
Innovation

Methods, ideas, or system contributions that make the work stand out.

Model Quantization
Model Inversion Attacks
Privacy-aware PTQ
Mutual Information
Bit Allocation
🔎 Similar Papers
No similar papers found.