Privacy-Preserving Inference on the Edge: Mitigating a New Threat Model