arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.18021cs.ITcs.CRmath.IT

用于合成数据生成的最优领域感知隐私机制

Optimal Domain-Aware Privacy Mechanisms for Synthetic Data Generation

Sajani Vithana, Sangwon Jung, Haoyang Hu, Viveck R. Cadambe, Flavio P. Calmon, Haewon Jeong

AI总结:

研究在合成数据生成中如何将公共数据纳入差分隐私机制,提出以归一化直方图为分布估计器,刻画特定类中的渐近最优领域感知隐私机制,引入PubMix机制,实验证明其显著提升合成数据生成质量。

AI中文摘要:

差分隐私(DP)在合成数据生成中在隐私和统计保真度之间带来了基本权衡。虽然经验表明访问公共数据可改善这些权衡,但现有方法仅通过预处理(如使用预训练生成模型)或后处理步骤(如匹配从公共数据集估计的目标统计量)间接使用公共数据,且依赖领域无关的DP机制。本文构建理论框架来研究将公共数据原则性地纳入DP机制本身。我们将归一化直方图视为分布估计器,并刻画了特定DP机制类中的渐近最优领域感知隐私机制。我们引入了PubMix,一种可用于基于直方图的数据合成管道的公共数据感知DP机制。实验表明,与领域无关的隐私机制相比,PubMix显著提高了合成数据生成质量。

英文摘要:

Differential privacy (DP) imposes fundamental trade-offs between privacy and statistical fidelity in synthetic data generation. While access to public data has been shown to improve these trade-offs empirically, existing approaches use public data only indirectly, through pre-processing (e.g., using pre-trained generative models) or post-processing steps (e.g., matching target statistics estimated from public datasets), while relying on domain-agnostic DP mechanisms. In this work, we lay the theoretical framework to study the principled incorporation of public data into DP mechanisms themselves. We consider normalized histograms as distribution estimators and characterize the asymptotically optimal domain-aware privacy mechanism within a specific class of DP mechanisms. We introduce PubMix, a public-data-aware DP mechanism that can be used in histogram-based data synthesis pipelines. Our experiments demonstrate that PubMix significantly improves synthetic data generation quality compared to domain-agnostic privacy mechanisms.

↑