arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

作为公平投入的隐私成本:差分隐私机器学习的群体公平性准则

Privacy Cost as Equity Input: A Group Fairness Criterion for Differentially Private Machine Learning

Rakshit Naidu

arXiv 2607.16620首次发表:更新:

AI 中文总结

研究差分隐私机器学习中群体公平性问题,提出基于隐私成本公平比率(PCER)的度量方法,该方法仅需每组训练和测试准确性,通过实验评估其与标准公平性度量的差异,揭示了基于结果度量遗漏的模式及隐私保证对审计的影响。

AI 中文摘要

差分隐私(DP)越来越多地用于限制机器学习系统中的成员推断风险。先前工作表明DP-SGD会扩大不同人口群体间的准确性差距,但这一框架将公平性仅视为结果端的问题。我们认为隐私成本,即每个群体所承受的信息泄露,本身就是一种伤害,并采用补偿公平框架,即非自愿承受更大隐私暴露的群体应从系统中获得相应更多的益处。基于此原则我们推导出隐私成本公平比率(PCER),这是一种群体公平性度量,定义为一个群体的正预测率除以其每组过拟合差距。通过标准成员推断界限,此过拟合差距为每个群体对推断攻击的脆弱性提供了上限,使得PCER成为相对于暴露的保守收益度量。PCER仅需要每组的训练和测试准确性(无需影子模型),使其成为一种实用的事后审计工具。我们在一系列隐私预算下,在DP-SGD中,跨六个涵盖表格和NLP领域的基准-属性组合,将PCER与标准公平性度量一起进行评估,并针对直接阈值成员推断攻击验证过拟合差距代理。结果揭示了基于结果的度量所遗漏的模式。在COMPAS上,PCER揭示了一种持续的双重劣势:受保护群体既承受更大的隐私暴露,又有更差的预测结果,而人口统计学均等差距完全掩盖了这一点。敏感性分析表明,非常强的隐私保证会使两个群体的过拟合都降至数值下限,使得基于暴露的审计在该情况下无信息价值。总之,这些发现表明,对隐私保护系统的公平性审计必须考虑谁承担保护成本,而不仅仅是谁从其结果中受益。

英文摘要

Differential privacy (DP) is increasingly deployed to limit membership inference risk in machine-learning systems. Prior work has shown that DP-SGD can widen accuracy disparities across demographic groups, but this framing treats fairness as a purely outcome-side concern. We argue that privacy cost, the information leakage borne by each group, is itself a form of harm, and adopt a compensatory-fairness framework in which a group that involuntarily bears greater privacy exposure is owed proportionally greater benefit from the system. From this principle we derive the \emph{Privacy-Cost Equity Ratio} (PCER), a group fairness metric defined as a group's positive prediction rate normalized by its per-group overfitting gap. By a standard membership inference bound, this overfitting gap upper-bounds each group's vulnerability to inference attacks, making PCER a conservative measure of benefit relative to exposure. PCER needs only per-group train and test accuracy (no shadow models), making it a practical post-hoc audit tool. We evaluate PCER alongside standard fairness metrics across six benchmark--attribute combinations spanning tabular and NLP domains, under DP-SGD at a range of privacy budgets, and validate the overfitting-gap proxy against a direct threshold membership-inference attack. The results reveal patterns that outcome-based metrics miss. On COMPAS, PCER uncovers a persistent double disadvantage: the protected group bears both greater privacy exposure and worse predictive outcomes, something demographic parity gap masks entirely. Sensitivity analysis shows very strong privacy guarantees collapse both groups' overfitting to a numerical floor, rendering exposure-based audits uninformative in that regime. Together, these findings show that fairness audits of privacy-preserving systems must account for who bears the cost of protection, not only who benefits from its outcomes.

CommentsAIES 2026 (accepted)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑