arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

具有参与隐私的持续学习:一种可审计的缓冲聚合方法

Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe

T-H. Hubert Chan, Elaine Shi, Mengshi Zhao, Mingxun Zhou

arXiv 2607.07209首次发表:更新:

发表机构

The University of Hong Kong; Carnegie Mellon University; The Hong Kong University of Science and Technology(香港大学; 卡内基梅隆大学; 香港科学与技术大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究单编辑相邻用户流的持续学习隐私问题,提出模块化方法,用随机缓冲包装器处理,证明认证定理,使标准原语产生轨迹级差分隐私,建立隐私与延迟联系。

AI 中文摘要

现代联邦和流学习系统经常发布中间模型,因此在自适应交互下隐私必须适用于整个轨迹。受参与隐私的启发,我们研究单编辑相邻用户流,其中一次插入/删除会改变所有后续更新并使标准汉明邻域持续发布分析失效。我们给出了一种可审计的模块化方法。一个随机缓冲包装器发出大小为$[U,2U]$的桶,将单编辑流减少为具有明确积压/延迟保证的每个桶的汉明风格更新流,其中$U$由隐私参数$(\varepsilon,\delta)$校准。然后我们证明了一个认证定理,确定何时连续原语的非自适应汉明邻域差分隐私证明适用于自适应输入:原语必须使用新鲜的每轮随机性,并且在常见自适应上下文中具有稳定的单轮隐私配置文件。总之,这些要素使用标准原语(例如树前缀和)为单编辑流产生轨迹级$(\varepsilon,\delta)$-差分隐私,并通过$U$建立明确的隐私-延迟联系。

英文摘要

Modern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor continual-release analyses. We give an auditable modular recipe. A randomized buffering wrapper emits bins of size $[U,2U]$, reducing single-edit streams to a Hamming-style per-bin update stream with explicit backlog/delay guarantees, where $U$ is calibrated by the privacy parameters $(\varepsilon,δ)$. We then prove a certification theorem identifying when a non-adaptive Hamming-neighbor DP proof for a continual primitive lifts to adaptive inputs: the primitive must use fresh per-round randomness and have a stable one-round privacy profile under common adaptive context. Together, these ingredients yield trajectory-level $(\varepsilon,δ)$-DP for single-edit streams using standard primitives (e.g., tree prefix sums), with an explicit privacy--latency link via $U$.

CommentsThis version corrects and clarifies the independent-decomposability condition underlying the adaptive-safety result in the pre-conference version of the ICML 2026 paper, with corresponding revisions to the affected statements and proofs

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑