arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.23382cs.LGcs.CR

面向隐私增强实例编码的可逆性的频谱感知界

Spectrum-Aware Bounds on Invertibility for Privacy-Enhancing Instance Encoding

Seokjin Hwang, Yuting Li, Kiwan Maeng

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对隐私增强实例编码的可逆性,提出考虑编码器频谱结构的新理论界,其更紧致且适用于确定性编码器,可扩展至其他范数度量,经多类实验验证优于现有界。

中文摘要 AI 辅助

实例编码是一种流行的隐私增强经验技术,用于在将数据共享至不可信服务器时,通过编码过程转换敏感数据,期望该过程保留效用同时难以重构原始数据。然而,多数工作未提供编码过程实际不可逆的理论保证,近期一项工作推导了均方误差(MSE)界以限制任意攻击者的重构精度,是该领域首批理论结果之一,但该界存在三个关键局限:常过于宽松、仅适用于随机编码器(排除从业者使用的许多确定性编码器)、仅限制MSE。我们引入一系列新的界,通过恰当考虑编码器的频谱结构,实现:(1)更紧致;(2)甚至适用于完全确定性编码器;(3)可从MSE扩展至其他基于范数的相似性度量。我们在一系列编码器、数据集和攻击中评估这些界,结果显示它们始终成立且优于现有界。

英文摘要

Instance encoding is a popular empirical technique for privacy enhancement when sharing data to an untrusted server. It transforms sensitive data through an encoding process before sharing, with the hope that the encoding process retains utility but makes it hard to reconstruct the original data. However, most work offers no theoretical guarantee that the encoding process is actually irreversible. A recent work derived a mean-squared error (MSE) bound limiting any adversary's reconstruction accuracy, offering one of the first theoretical results in this domain. This bound, however, has three critical limitations: it is often too loose, only works with randomized encoders (excluding many deterministic encoders practitioners use), and only bounds MSE. We introduce a family of new bounds that (1) are tighter, (2) applicable even to fully deterministic encoders, and (3) can extend beyond MSE to other norm-based similarity metrics, by properly accounting for the encoder's spectral structure. We evaluate our bounds across a range of encoders, datasets, and attacks, showing they hold consistently and improve upon the existing bound.

发表机构

  • The Pennsylvania State University(宾夕法尼亚州立大学)

机构由 AI 辅助整理,请以论文原文为准。

↑