A Security Analysis of CNN Partitioning Strategies for Distributed Inference at the Edge
Security, Privacy, and Applied Cryptography Engineering (SPACE 2025), Guwahati, India. Springer Nature Switzerland, 2026, pp. 262–281.
Key result
Data partitioning leaked the least reconstructable input information, while vertical partitioning was the most vulnerable across the evaluated models and datasets.
Listen or watch first
Conversational overviews generated from the paper with Google NotebookLM. They are a way in, not a substitute: the numbers and claims that matter are in the paper itself.
Abstract
The inference of Convolutional Neural Networks (CNNs) at the Edge poses significant challenges due to resource limitations of edge devices. One approach to addressing these challenges is to distribute a CNN model across multiple edge devices. While much attention has been paid to improving the performance, memory utilization, energy efficiency, and robustness of distributed CNN inference at the Edge, security implications of such inference remain largely unexplored. Therefore, in this paper, we investigate the security vulnerabilities of the three main partitioning strategies for distributing CNN models across multiple edge devices, namely vertical partitioning, horizontal partitioning, and data partitioning. More specifically, we assess how accurately an attacker can reconstruct the input image given to a CNN model and predict the image class by eavesdropping on the communication link between two edge devices. We devise a simple, yet realistic attack scenario in which the attacker attempts to reconstruct the input image from intermediate data obtained from the communication link. In order to evaluate the vulnerability of the system, the reconstructed image is fed back into the model to see if its class can be determined. We conduct extensive experiments using different CNN models and datasets. Our results show that data partitioning is less vulnerable to this attack scenario compared to the other partitioning strategies, while vertical partitioning is the most vulnerable.
Keywords Distributed edge computing · Neural networks · Security
Cite this paper
IEEE
F. Mehrafrooz, R. Siyadatzadeh, N. Mentens and T. Stefanov, "A Security Analysis of CNN Partitioning Strategies for Distributed Inference at the Edge," in Security, Privacy, and Applied Cryptography Engineering (SPACE 2025) (Lecture Notes in Computer Science, vol. 16406), Guwahati, India, 2026, pp. 262-281, doi: 10.1007/978-3-032-16342-4_15.
APA
Mehrafrooz, F., Siyadatzadeh, R., Mentens, N., & Stefanov, T. (2026). A Security Analysis of CNN Partitioning Strategies for Distributed Inference at the Edge. In Security, Privacy, and Applied Cryptography Engineering (SPACE 2025) (pp. 262–281). Springer Nature Switzerland. https://doi.org/10.1007/978-3-032-16342-4_15
BibTeX
@inproceedings{mehrafrooz2025partitioning,
author = {Mehrafrooz, Fatemeh and Siyadatzadeh, Roozbeh and Mentens, Nele and Stefanov, Todor},
title = {A Security Analysis of {CNN} Partitioning Strategies for Distributed Inference at the Edge},
booktitle = {Security, Privacy, and Applied Cryptography Engineering (SPACE 2025)},
series = {Lecture Notes in Computer Science},
volume = {16406},
year = {2026},
pages = {262--281},
publisher = {Springer Nature Switzerland},
address = {Guwahati, India},
doi = {10.1007/978-3-032-16342-4_15},
url = {https://doi.org/10.1007/978-3-032-16342-4_15},
}Details
- Published
- Venue
- Security, Privacy, and Applied Cryptography Engineering (SPACE 2025)
- Series
- Lecture Notes in Computer Science, vol. 16406
- Pages
- 262–281
- Publisher
- Springer Nature Switzerland
- Citations
- None indexed yet Semantic Scholar Graph API, 2026-09-02
For agents and tools
- Markdown record (OKF)
- BibTeX
- PDF Author manuscript
- JSON-LD and Google Scholar tags are embedded in this page.