举报人似是而非的可否认性保障
Plausible Deniability Guarantees for Whistleblowers
查看机构详情
- University College London(伦敦大学学院)
- École Polytechnique de Montréal(蒙特利尔理工学院)
- Mila - Québec Artificial Intelligence Institute(魁北克人工智能研究所)
机构由 AI 辅助整理,请以论文原文为准。
浏览论文内容
中文总结 AI 辅助
研究如何保障举报人,针对现有保护提案和差分隐私机制不足,形式化逐报告(0,δ)-差分隐私,证明随机响应不比均匀随机审计好超δ,给出通用机制简化私人审计,实例化后有良好效果,模拟显示优于随机响应。
中文摘要 AI 辅助
举报人是防止组织不当行为的关键保障,但报复威胁阻碍了举报行为。现有举报人保护提案缺乏正式隐私保障,现有差分隐私机制未直接针对自然威胁模型,即被审计组织自身观察审计人员选择决定并据此识别举报人。我们将针对强对手威胁模型的保护形式化为审计选择记录上的逐报告(0,δ)-差分隐私。在此框架内,我们证明在任何时间范围内,一种自然方法——在选择步骤应用随机响应——永远不会比均匀随机审计表现好超过δ。然后我们给出一种通用机制,将私人审计简化为私人连续计数:任何(0,δ)-DP连续计数器通过后处理插入,审计记录继承相同的逐报告保障。用连续计数中的一项近期工作实例化这种简化,在T次审计决策的时间范围内产生逐报告(0,δ)-DP,噪声缩放为O(√log T)。一个效用定理表明,只要报告最多的组织与第二名之间的噪声报告差距增长快于√log T,选择误差就会消失。模拟显示比随机响应有显著改进。
英文摘要
Whistleblowers are a key safeguard against organizational wrongdoing, but the threat of retaliation deters reporting. Existing whistleblower-protection proposals lack formal privacy guarantees, and existing differential privacy mechanisms do not directly target the natural threat model -- one in which the audited organization itself observes auditor selection decisions and uses them to identify reporters. We formalize protection against a strong-adversary threat model as per-report $(0, δ)$-differential privacy on the transcript of audit selections. Within this framework we prove that a natural approach -- randomized response applied at the selection step -- can never outperform uniform random auditing by more than $δ$ at any horizon. We then give a generic mechanism that reduces private auditing to private continual counting: any $(0, δ)$-DP continual counter plugs in by post-processing, and the audit transcript inherits the same per-report guarantee. Instantiating the reduction with a recent work in continual counting yields per-report $(0, δ)$-DP with noise scaling as $O(\sqrt{\log T})$ across a horizon of $T$ audit decisions. A utility theorem shows that the selection error vanishes whenever the noisy report gap between the most-reported organization and the runner-up grows faster than $\sqrt{\log T}$. Simulations show a substantial improvement over randomized response.