arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.27815stat.MLcs.LG

局部差分隐私下稀疏数值向量的鲁棒估计

Robust Estimation of Sparse Numerical Vectors under Local Differential Privacy

  • Shenzhen Campus of Sun Yat-sen University(中山大学深圳校区)
  • Zhejiang University(浙江大学)
  • Guangzhou University(广州大学)
  • National Interdisciplinary Research Center of Engineering Physics(国家工程物理学跨学科研究中心)
  • Anhui University of Science and Technology(安徽理工大学)

机构由 AI 辅助整理,请以论文原文为准。

Puning Zhao, Zhikun Zhang, Shaowei Wang, Sheng Yue, Bangzhou Xin, Tianhang Zheng, Pengfei Zhang, Xiaochun Cao

AI总结:

本文针对局部差分隐私下多项用户的稀疏向量均值估计问题,提出带裁剪的随机投影方法,通过偏差校正实现更优鲁棒性,实验验证其在可信与不可信环境中均表现良好。

AI中文摘要:

局部差分隐私(LDP)协议易受投毒攻击。现有研究已提出针对单项用户的高效防御策略,但实际中用户可能拥有多项数据。针对多项用户的投毒攻击防御极具挑战性,因为更大的输出空间会使攻击者发动更难被检测的强力攻击。本文研究鲁棒稀疏向量均值估计问题,其中每个用户拥有含 m 个非零坐标的向量。我们提出带裁剪的随机投影(RPC)方法:服务器向每位用户发送随机二进制向量,用户将本地数据投影到该向量并裁剪值以限制攻击者能力;为处理裁剪偏差,我们提出基于细致分析的校正方法,给出偏差的精确表达式,从而无需权衡偏差-方差,可进一步降低裁剪阈值以缩小输出空间、增强鲁棒性。我们提供了针对所有可能攻击下估计误差的严格理论保证。数值实验表明,在可信环境中,该方法性能与现有方法相当或更优,本身已是高效估计器;在不可信环境中,其对投毒攻击的鲁棒性也显著更强。

英文摘要:

Local differential privacy (LDP) protocols are vulnerable to poisoning attacks. Existing research have proposed efficient defense strategies for single-item users. However, in practice, a user may possess multiple items. The defense against poisoning attacks for multi-item users is challenging, because due to larger output spaces, the adversary can conduct more powerful attacks without being detected. In this paper, we address the robust sparse vector mean estimation problem, in which each user has a vector with $m$ nonzero coordinates. We propose Randomized Projection with Clipping (RPC). Firstly, the server sends a random binary vector to each user. The user then projects its local data on the vector, and clip the value to restrict the attacker's capability. To handle clipping bias, we propose a correction method based on a careful analysis that gives an exact expression of the bias. As a result, bias-variance tradeoff is no longer needed, thus the clipping threshold can be further reduced to shrink the output space and enhance robustness. We provide a rigorous theoretical guarantee of the estimation error under all possible attacks. Numerical experiments show that under trusted environments, our new method achieves comparable or better performance than existing methods, indicating that our method is already an efficient estimator in its own right. Under untrusted environments, our method is also significantly more robust to poisoning attacks.

↑