SynthGuard-ReleaseBench:合成表格数据发布的锁定审计证据
SynthGuard-ReleaseBench: Locked-Audit Evidence for Synthetic Tabular Data Releases
浏览论文内容
中文总结 AI 辅助
本文提出SynthGuard-ReleaseBench审计框架,通过锁定审计要素对比工作流,在多类数据上验证其可复现性与区分性,为合成表格数据发布提供特定用途的审计证据。
中文摘要 AI 辅助
合成表格数据通常依据真实性、隐私性或下游任务评分进行评判,但这些评分无法回答拟议发布是否支持特定用途、特定人群及威胁模型。本文提出SynthGuard-ReleaseBench,这一审计框架在评估前锁定用途、候选面板、容差及审计时间表,对比受保护数据上的真实训练与合成训练工作流,给出有界损失差距的同时有限样本界,要求设置对照组,并将效用、经验隐私风险、机制声明及人工发布权限分离。在四项美国社区调查(ACS)研究、五项非ACS记录、两项时间诊断及一个密封原型中,该基准保留了有利、不利及排除结果:透明基线通过部分锁定审计;紧凑学习模型在声明预算下失败;健康表案例因阴性对照通过而被排除。跨三个生成种子重复的审计后扩展分支显示,当学习模型在足够数据上拟合后,相同锁定准则会接纳它们,但仍会在所有规模下拒绝依赖破坏型对照,表明该准则具有区分性而非仅拒绝;相同重复会取消更精细的单种子排序。理论部分增加了预审计样本量规则、方差自适应且随时有效的证书(在相同锁定证据上将界收紧2至10倍)、时间排序审计的时间证书,以及两个下界:当查询预算达到其规模时,普通有界查询会重构受保护审计,且面板大小校正为必要而非保守。本文的贡献是一种可复现的特定用途发布证据工作流,而非声称任何生成器是私密、安全或可部署的。
英文摘要
Synthetic tabular data are often judged by realism, privacy, or downstream-task scores. Those scores do not answer whether a proposed release is supported for a named use, population, and threat model. We introduce SynthGuard-ReleaseBench, an audit framework that locks the use, candidate panel, tolerances, and audit schedule before evaluation. It compares real-trained and synthetic-trained workflows on protected data, gives simultaneous finite-sample bounds for bounded loss gaps, requires controls, and keeps utility, empirical privacy risk, mechanism claims, and human release authority separate. Across four American Community Survey studies, five non-ACS records, two chronological diagnostics, and a sealed prototype, the benchmark retains favorable, unfavorable, and excluded outcomes. Transparent baselines pass some locked audits; compact learned models fail under the declared budgets; a health-table case is excluded because its negative control passes. A post-audit scaling arm, repeated across three generation seeds, shows the same locked criterion admitting those learned models once they are fit on enough data while still rejecting a dependence-destroying control at every size, so the criterion discriminates rather than merely rejects; the same repetition withdraws a finer single-seed ordering. The theory adds a pre-audit sample-size rule, variance-adaptive and anytime-valid certificates that tighten the bound two to ten times on the same locked evidence, a temporal certificate for time-ordered audits, and two lower bounds: ordinary bounded queries reconstruct a protected audit once the query budget reaches its size, and the panel-size correction is necessary rather than conservative. The contribution is a reproducible workflow for use-specific release evidence, not a claim that any generator is private, safe, or deployment-ready.