{"id":{"repo_id":"mit","oai_identifier":"oai:dspace.mit.edu:1721.1/139497"},"canonical_url":"https://search.dev.ndltd.org/etd/mit/oai:dspace.mit.edu:1721.1/139497","repository":{"repo_id":"mit","name":"MIT","base_url":"https://dspace.mit.edu/oai/request"},"display":{"title":"Computational Privacy with Split Learning: Benchmarking of Algorithmic Defenses against Reconstruction Attacks","abstract":"Distributed deep learning has potential for significant impact in preserving data privacy and improving model accuracy by leveraging massive sets of training data. However, passing intermediate weights, gradients, or activations is inherent in current distributed learning techniques, all of which contain information related to input data. This thesis analyzes split learning, a current state of the art distributed deep learning technique, in the context of the private collaborative inference scheme against reconstruction attacks. This is achieved by creating a benchmark and introducing new methods of improving privacy algorithmically. Benchmarking is done by comparing input data reconstruction quality and accuracy of sensitive attribute prediction over the axes of number of activation, input data pairs are leaked, and whether or not model parameters and general data distribution information is known. The proposed privacy improvements involve changes in model training to leak less information that may be used for reconstruction while preserving accuracies for the originally intended model prediction task. These improvements are compared against current state of the art privacy methods in protection over various reconstruction attacks.","abstract_html":"Distributed deep learning has potential for significant impact in preserving data privacy and improving model accuracy by leveraging massive sets of training data. However, passing intermediate weights, gradients, or activations is inherent in current distributed learning techniques, all of which contain information related to input data. This thesis analyzes split learning, a current state of the art distributed deep learning technique, in the context of the private collaborative inference scheme against reconstruction attacks. This is achieved by creating a benchmark and introducing new methods of improving privacy algorithmically. Benchmarking is done by comparing input data reconstruction quality and accuracy of sensitive attribute prediction over the axes of number of activation, input data pairs are leaked, and whether or not model parameters and general data distribution information is known. The proposed privacy improvements involve changes in model training to leak less information that may be used for reconstruction while preserving accuracies for the originally intended model prediction task. These improvements are compared against current state of the art privacy methods in protection over various reconstruction attacks.","abstract_has_math":false,"creators":["Zhang, Emily T."],"institution":"Massachusetts Institute of Technology","degree_name":"Master","degree_level":null,"degree_discipline":null,"degree_department":"Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science","school":null,"contributors":[],"advisors":["Raskar, Ramesh"],"committee_chairs":[],"committee_members":[],"year":2021,"date_issued":"2021-06","date_published":"2021-06","updated_at":"2026-07-22T22:22:13Z","subjects":[],"languages":[],"rights":["In Copyright - Educational Use Permitted","Copyright MIT"],"rights_urls":["http://rightsstatements.org/page/InC-EDU/1.0/"],"identifier_entries":[]},"links":{"outbound_url":"https://hdl.handle.net/1721.1/139497","outbound_label":"Handle","outbound_source":"dc:identifier.uri"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor.advisor","label":"Advisor","values":["Raskar, Ramesh"]},{"key":"dc:contributor.department","label":"Department","values":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science"]},{"key":"dc:creator","label":"Author","values":["Zhang, Emily T."]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date.accessioned","label":"Dc Date Accessioned","values":["2022-01-14T15:15:35Z"]},{"key":"dc:date.available","label":"Dc Date Available","values":["2022-01-14T15:15:35Z"]},{"key":"dc:date.issued","label":"Date","values":["2021-06"]},{"key":"dc:publisher","label":"Institution","values":["Massachusetts Institute of Technology"]},{"key":"dc:type","label":"Dc Type","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Master","Master of Engineering in Electrical Engineering and Computer Science"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:rights","label":"Dc Rights","values":["In Copyright - Educational Use Permitted","Copyright MIT"]},{"key":"dc:rights.uri","label":"Rights URI","values":["http://rightsstatements.org/page/InC-EDU/1.0/"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier.uri","label":"Identifier URI","values":["https://hdl.handle.net/1721.1/139497"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description.abstract","label":"Abstract","values":["Distributed deep learning has potential for significant impact in preserving data privacy and improving model accuracy by leveraging massive sets of training data. However, passing intermediate weights, gradients, or activations is inherent in current distributed learning techniques, all of which contain information related to input data. This thesis analyzes split learning, a current state of the art distributed deep learning technique, in the context of the private collaborative inference scheme against reconstruction attacks. This is achieved by creating a benchmark and introducing new methods of improving privacy algorithmically. Benchmarking is done by comparing input data reconstruction quality and accuracy of sensitive attribute prediction over the axes of number of activation, input data pairs are leaked, and whether or not model parameters and general data distribution information is known. The proposed privacy improvements involve changes in model training to leak less information that may be used for reconstruction while preserving accuracies for the originally intended model prediction task. These improvements are compared against current state of the art privacy methods in protection over various reconstruction attacks."]},{"key":"dc:description.degree","label":"Dc Description Degree","values":["M.Eng."]},{"key":"dc:title","label":"Title","values":["Computational Privacy with Split Learning: Benchmarking of Algorithmic Defenses against Reconstruction Attacks"]}]}],"canonical_facts":{"dc:contributor.advisor":["Raskar, Ramesh"],"dc:contributor.department":["Massachusetts Institute of Technology. Department of Electrical Engineering and Computer Science"],"dc:creator":["Zhang, Emily T."],"dc:date.accessioned":["2022-01-14T15:15:35Z"],"dc:date.available":["2022-01-14T15:15:35Z"],"dc:date.issued":["2021-06"],"dc:description.abstract":["Distributed deep learning has potential for significant impact in preserving data privacy and improving model accuracy by leveraging massive sets of training data. However, passing intermediate weights, gradients, or activations is inherent in current distributed learning techniques, all of which contain information related to input data. This thesis analyzes split learning, a current state of the art distributed deep learning technique, in the context of the private collaborative inference scheme against reconstruction attacks. This is achieved by creating a benchmark and introducing new methods of improving privacy algorithmically. Benchmarking is done by comparing input data reconstruction quality and accuracy of sensitive attribute prediction over the axes of number of activation, input data pairs are leaked, and whether or not model parameters and general data distribution information is known. The proposed privacy improvements involve changes in model training to leak less information that may be used for reconstruction while preserving accuracies for the originally intended model prediction task. These improvements are compared against current state of the art privacy methods in protection over various reconstruction attacks."],"dc:description.degree":["M.Eng."],"dc:identifier.uri":["https://hdl.handle.net/1721.1/139497"],"dc:publisher":["Massachusetts Institute of Technology"],"dc:rights":["In Copyright - Educational Use Permitted","Copyright MIT"],"dc:rights.uri":["http://rightsstatements.org/page/InC-EDU/1.0/"],"dc:title":["Computational Privacy with Split Learning: Benchmarking of Algorithmic Defenses against Reconstruction Attacks"],"dc:type":["Thesis"],"thesis:degree_name":["Master","Master of Engineering in Electrical Engineering and Computer Science"]},"updated_at":"2026-07-22T22:22:13Z"}