arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

球差分隐私:如何用更少噪声减轻数据重建

Ball Differential Privacy: How to Mitigate Data Reconstruction with Less Noise

Joseph Margaryan, Nirupam Gupta

arXiv 2607.04209首次发表:更新:

AI 中文总结

研究如何缓解数据重建问题,提出球差分隐私方法,通过限制单记录替换范围减少噪声,给出正则化凸学习问题的噪声校准及重建稳健性证书,并在基准学习任务上验证,提高了效用。

AI 中文摘要

原始记录的向量嵌入虽不可读但不保护隐私,对手可从发布模型重建训练记录。差分隐私是防御方法,但噪声针对最坏情况,远超重建所需。我们提出球差分隐私,在嵌入空间中对半径为r的球内单记录替换强制实现ε-δ不可区分性,给出噪声校准及重建稳健性证书并验证。

英文摘要

Vector embeddings of raw records, while not human-readable, do not preserve record privacy: an adversary can reconstruct training records from a released model even when that model is a simple convex classifier. Differential privacy (DP) is the principled defense, but its noise is calibrated to worst-case indistinguishability, hiding arbitrary single-record substitutions, including those far outside the set of plausible alternatives relevant to a reconstruction adversary. The result is noise far larger than what reconstruction robustness requires, degrading accuracy without a corresponding security benefit. We propose Ball-DP: enforcing epsilon-delta indistinguishability over single-record substitutions restricted to a ball of radius r under a distance metric d in the embedding space. A deployment facing only local reconstruction threats can choose a small r, thereby reducing noise and recovering accuracy. The radius makes the scope of the privacy claim explicit against reconstruction attacks; standard DP is recovered when r covers the entire admissible record domain. We provide noise calibrations for regularized convex learning problems under Ball-DP, and derive corresponding reconstruction-robustness certificates, called Ball-ReRo, that upper-bound an attacker's reconstruction success. By deriving the optimal finite-prior MAP reconstruction attack, we empirically audit Ball-ReRo certificates on seven benchmark learning tasks. Our experiments show that calibrating noise to Ball-DP improves utility, considerably exceeding the dilution of reconstruction robustness in high-privacy regimes, i.e., when epsilon is small.

Comments44 pages, 4 figures; references standardized

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑