发表机构
London Metropolitan University; School of Computing and Digital Media(伦敦都市大学; 计算与数字媒体学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对金融欺诈检测中联邦学习结合TreeSHAP解释易受成员推理攻击的问题,提出客户端级差分隐私的DP-FedSHAP架构,权衡解释保真度、隐私与AUPRC性能。
AI 中文摘要
金融欺诈检测严重依赖集中式机器学习模型,这带来了严重的数据隐私风险。联邦学习(FL)将数据处理去中心化,但金融监管仍要求模型具备可解释性,即使用TreeSHAP等可解释人工智能(XAI)工具。近期网络安全研究表明,该方法存在问题:高保真SHAP解释的共享会使联邦网络面临成员推理攻击(MIAs)。本论文提出并评估了DP-FedSHAP,这是一种仅对事后TreeSHAP向量应用客户端级差分隐私的新架构。将其与直接扰动训练模型的权重级差分隐私基线进行比较,使用高度不平衡的IEEE-CIS欺诈检测数据集,研究测量了解释保真度、隐私保护与模型精确召回曲线下面积(AUPRC)之间的权衡关系。
英文摘要
Financial fraud detection relies heavily on centralized machine learning models. This creates serious data privacy risks. Federated Learning (FL) decentralizes data processing, but financial regulations still require models to be transparent. This means using Explainable AI (XAI) tools such as TreeSHAP. Recent cybersecurity research shows a problem with this approach. Sharing high-fidelity SHAP explanations exposes the federated network to Membership Inference Attacks (MIAs). This dissertation proposes and evaluates DP-FedSHAP. It is a new architecture that applies client-level differential privacy only to post-hoc TreeSHAP vectors. It is compared against a Weight-Level DP baseline, which perturbs the trained model directly instead. Using the highly imbalanced IEEE-CIS Fraud Detection dataset, this study measures the trade-off between explanation fidelity, privacy preservation, and the model's Area Under the Precision-Recall Curve (AUPRC).