PrivateHub:用于生成隐私保护型密集传感器环境数据的对比扩散模型
PrivateHub: Contrastive Diffusion Model for Private Sensor-Intensive Environment Data Generation
浏览论文内容
中文总结 AI 辅助
PrivateHub是一种对比扩散模型,可生成隐私保护型多传感器数据流,在不损害非隐私应用性能的前提下降低隐私应用推断准确率40%-50%,且具备对抗攻击者重训练的鲁棒性。
中文摘要 AI 辅助
密集传感器环境通过从异构数据流中推断用户应用,为众多智能服务提供支撑。然而,并非所有应用都应被暴露:用户希望部分活动保持隐私,这就造成了为有用服务推断应用与防止非预期推断之间的矛盾。现有方法如差分隐私、基于规则的过滤仅能保护单个数据流,无法解决跨传感器推断带来的隐私风险。我们提出PrivateHub,该方法在扩散模型中使用对比学习生成合成多传感器数据流,在保持非隐私应用可被检测的同时隐藏隐私应用。PrivateHub包含两个阶段:应用条件预训练(ACP),该阶段通过应用嵌入将模型以多传感器数据为条件;应用感知微调(AAF),该阶段通过对比学习将隐私数据与非隐私数据分离。我们还定义了多传感器共享场景下的威胁模型。在三个真实多传感器数据集上的实验表明,PrivateHub可将隐私应用的推断准确率降低40%至50%,同时不影响非隐私应用的性能,且在攻击者基于合成数据重新训练时仍保持鲁棒性。
英文摘要
Sensor-intensive environments enable many intelligent services by inferring user applications from heterogeneous data streams. However, not all applications should be exposed: users want some activities to stay private. This creates a tension between inferring applications for useful services and preventing unwanted inference. Existing approaches such as differential privacy and rule-based filtering protect individual streams but cannot address the privacy risk from cross-sensor inference. We introduce Privatehub, which uses contrastive learning within a diffusion model to generate synthetic multi-sensor streams that keep non-private applications detectable while concealing private ones. Privatehub has two stages: App-Conditioned Pre-training (ACP), which conditions the model on multi-sensor data with application embeddings, and App-Aware Fine-tuning (AAF), which separates private from non-private data via contrastive learning. We also define a threat model for the multi-sensor sharing setting. Experiments on three real-world multi-sensor datasets show Privatehub lowers private-application accuracy by 40 to 50\% without hurting non-private performance, and stays robust when the attacker retrains on the synthetic data.
发表机构
- Stanford University(斯坦福大学)
- University of Virginia(弗吉尼亚大学)
机构由 AI 辅助整理,请以论文原文为准。