DDP-CEM: Dual-Path Privacy Protection for Collaborative Face Inference
A split model sends an intermediate representation from a trusted client to an untrusted server. Strong noise makes that tensor hard to invert but also removes what the server needs for recognition. DualPath-CEM separates the two jobs: a Gaussian-protected spatial path carries the privacy burden, a compact semantic token carries utility, and the server fuses two classifiers with calibrated logits. The attacker is assumed to see both released tensors.
- Top-1
- 81.96%
- Δ vs CEM
- +1.63 pts
- Decoder MSE
- +75.8%
- GAN MSE
- +74.9%
| Method | Top-1 ↑ | Decoder MSE ↑ inference | GAN MSE ↑ inference |
|---|---|---|---|
| Noise_ARL + CEM published | 80.33% | 0.0211 | 0.0231 |
| DualPath-CEM this work | 81.96% | 0.0371 | 0.0404 |
Evidence boundary
The reference row is the published CEM result, not a local reproduction. All five adaptations start from the same frozen SlotCEM foundation, so they are not independent end-to-end runs. The completed snapshot is FaceScrub-only. The evidence package covers 70 main attack runs, 15 repeated utility evaluations, 96 supplementary attack runs, a matched-capacity control and a ResNet-18 control.