Diffusion-based Task-oriented Semantic Communications with Model Inversion Attack

📅 2025-06-24
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
To address privacy leakage caused by model inversion attacks in task-oriented semantic communication for 6G, this paper proposes DiffSem—a framework that enhances semantic-level privacy protection without compromising downstream task accuracy. Methodologically, DiffSem integrates a diffusion-based generative mechanism with self-referential label embedding to achieve high-fidelity semantic reconstruction; introduces a novel semantic-consistency metric to expose the inadequacy of conventional image-quality metrics (e.g., PSNR, SSIM) for quantifying semantic leakage; and incorporates channel-noise compensation alongside controllable semantic distortion. Experimental results demonstrate a 10.03% improvement in classification accuracy on MNIST while maintaining robustness under dynamic channel conditions. To the best of our knowledge, DiffSem is the first framework to jointly optimize semantic privacy preservation, task performance, and transmission efficiency in 6G semantic communication.

Technology Category

Application Category

📝 Abstract
Semantic communication has emerged as a promising neural network-based system design for 6G networks. Task-oriented semantic communication is a novel paradigm whose core goal is to efficiently complete specific tasks by transmitting semantic information, optimizing communication efficiency and task performance. The key challenge lies in preserving privacy while maintaining task accuracy, as this scenario is susceptible to model inversion attacks. In such attacks, adversaries can restore or even reconstruct input data by analyzing and processing model outputs, owing to the neural network-based nature of the systems. In addition, traditional systems use image quality indicators (such as PSNR or SSIM) to assess attack severity, which may be inadequate for task-oriented semantic communication, since visual differences do not necessarily ensure semantic divergence. In this paper, we propose a diffusion-based semantic communication framework, named DiffSem, that optimizes semantic information reconstruction through a diffusion mechanism with self-referential label embedding to significantly improve task performance. Our model also compensates channel noise and adopt semantic information distortion to ensure the robustness of the system in various signal-to-noise ratio environments. To evaluate the attacker's effectiveness, we propose a new metric that better quantifies the semantic fidelity of estimations from the adversary. Experimental results based on this criterion show that on the MNIST dataset, DiffSem improves the classification accuracy by 10.03%, and maintain stable performance under dynamic channels. Our results further demonstrate that significant deviation exists between traditional image quality indicators and the leakage of task-relevant semantic information.
Problem

Research questions and friction points this paper is trying to address.

Preserving privacy while maintaining task accuracy in semantic communication
Assessing attack severity inadequately with traditional image quality indicators
Improving robustness and performance in dynamic channel environments
Innovation

Methods, ideas, or system contributions that make the work stand out.

Diffusion-based semantic communication framework
Self-referential label embedding mechanism
Semantic information distortion for robustness
🔎 Similar Papers
No similar papers found.
X
Xuesong Wang
School of Science and Engineering, The Chinese University of Hong Kong, Shenzhen, Guangdong 518172, China
M
Mo Li
School of Science and Engineering, The Chinese University of Hong Kong, Shenzhen, Guangdong 518172, China
X
Xingyan Shi
School of Science and Engineering, The Chinese University of Hong Kong, Shenzhen, Guangdong 518172, China
Zhaoqian Liu
Zhaoqian Liu
CUHKsz
S
Shenghao Yang
School of Science and Engineering, The Chinese University of Hong Kong, Shenzhen, Guangdong 518172, China