Zhang, Huaizhi and Zhu, Xuqi and Zhu, Jiacheng and McDonald-Maier, Klaus and Zhai, Xiaojun (2025) A Privacy-aware Quantilisation Approach for Efficient Edge Deep Learning Accelerator. In: 2025 IEEE International Symposium on Circuits and Systems (ISCAS), 2025-05-25 - 2025-05-28, London, United Kingdom.
Zhang, Huaizhi and Zhu, Xuqi and Zhu, Jiacheng and McDonald-Maier, Klaus and Zhai, Xiaojun (2025) A Privacy-aware Quantilisation Approach for Efficient Edge Deep Learning Accelerator. In: 2025 IEEE International Symposium on Circuits and Systems (ISCAS), 2025-05-25 - 2025-05-28, London, United Kingdom.
Zhang, Huaizhi and Zhu, Xuqi and Zhu, Jiacheng and McDonald-Maier, Klaus and Zhai, Xiaojun (2025) A Privacy-aware Quantilisation Approach for Efficient Edge Deep Learning Accelerator. In: 2025 IEEE International Symposium on Circuits and Systems (ISCAS), 2025-05-25 - 2025-05-28, London, United Kingdom.
Abstract
Data privacy is one of the key concerns in machine learning model applications at the edge, especially in sensitive domains such as the healthcare sector. Here adversaries may exploit Membership Inference Attacks (MIAs) to determine if particular data points were used as part of datasets from the model’s training set, potentially leading to further data leakage issues. Although privacy preservation techniques like differential privacy (DP) can mitigate such risks during the training phase, this often results in degradation of model accuracy, making them less suitable for cloud training and edge deployment paradigms. For AI edge applications, existing research works for designing neural network accelerators primarily prioritize computational performance and power efficiency as their design target. In this paper, we introduce a novel privacy-aware quantilisation approach for deep learning accelerators and analyse the tradeoff between computational efficiency and privacy protection. The proposed system allows to adjust privacy constraints through tunable parameters, enabling flexible deployment on edge devices while meeting privacy and performance constraints. We have evaluated the proposed design on an AMD VCK190 board using a range of hypothetical MIA benchmarks. The results demonstrate that the proposed approach can effectively reduce the success rate of MIA attacks across multiple performance metrics.
| Item Type: | Conference or Workshop Item (Paper) |
|---|---|
| Uncontrolled Keywords: | Training, Deep learning, Privacy, Quantization (signal), Neural networks, Medical services, Data models, Computational efficiency, Protection, Hardware acceleration |
| Subjects: | Z Bibliography. Library Science. Information Resources > ZR Rights Retention |
| Divisions: | Faculty of Science and Health Faculty of Science and Health > Computer Science and Electronic Engineering, School of |
| SWORD Depositor: | Unnamed user with email elements@essex.ac.uk |
| Depositing User: | Unnamed user with email elements@essex.ac.uk |
| Date Deposited: | 02 Sep 2026 09:43 |
| Last Modified: | 02 Sep 2026 10:46 |
| URI: | http://repository.essex.ac.uk/id/eprint/43781 |
Available files
Filename: ISCAS_2025.pdf
Licence: Creative Commons: Attribution 4.0