arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

差分隐私合成文本的子组隶属推断审计

Subgroup Membership Inference Audits of Differentially Private Synthetic Text

Yidan Sun, Viktor Schlegel, Srinivasan Nandakumar, Siew Kei Lam, Anil Anthony Bharath

arXiv 2609.09848首次发表:更新:

发表机构

Imperial College London; Nanyang Technological University(帝国理工学院; 南洋理工大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本研究定义子组定向隶属推断博弈,审计差分隐私合成文本,发现子组泄露被低估且集中于少数记录,DP保护不均匀,记录风险依赖发布机制。

AI 中文摘要

合成数据发布在文献中日益被提出作为一种共享真实数据副本以替代敏感私有数据集的手段。即使此类发布的最坏情况隐私泄露通过差分隐私(DP)得以限制,在实践中仍存在残余风险。隶属推断攻击(MIA)审计被用于实证量化这一风险。然而,现有方法仅衡量随机抽取记录的平均风险,这可能掩盖对脆弱子组的风险。为突出此问题,我们定义了一个子组定向隶属推断博弈,其中目标池是显式参数,并通过在四种数据集、三种生成器(DP-SGD微调、基于API的提示和激活引导)及五种隐私预算下,对32个代理在三种不同攻击者知识水平场景中进行审计来实例化该博弈。审计表明,合成发布泄露子组成员身份,且先前攻击系统性低估了此泄露。DP在聚合层面有效:在我们测试的每个预算下,它大幅减少了平均泄露。三点观察削弱了这一图景。首先,剩余泄露是集中而非分散的:在DP下,十分之一的记录承载了约40%的泄露。其次,DP在实践中提供的保护是不均匀的:在其最坏情况保证内,噪声从随机记录中移除的测量泄露多于高风险记录——而一个合并池审计对两种记录类型使用共享负样本进行评分,在记录层面证实了这一点。第三,哪些记录泄露被证明是发布机制的特性而非记录本身的特性,因此记录级风险不能独立于发布来评估。

英文摘要

Synthetic data releases are increasingly proposed in the literature as a means of sharing realistic data replicas in lieu of sensitive private datasets. Even when the worst-case privacy leakage of such releases is bounded by means of differential privacy (DP), in practice a residual risk remains. Membership inference attack (MIA) audits are conducted to empirically quantify this risk. However, existing methods only measure average-case risk for randomly drawn records, which might conceal the risk to vulnerable subgroups. To highlight this issue, we define a subgroup-targeted membership inference game in which the target pool is an explicit parameter, and instantiate it with an audit of 32 proxies under three scenarios with different levels of attacker knowledge, across four datasets, three generators (DP-SGD fine-tuning, API-based prompting, and activation steering), and five privacy budgets. The audit shows that synthetic releases leak subgroup membership and that prior attacks systematically underestimate this leakage. DP is effective at the aggregate level: it substantially reduces average leakage at every budget we test. Three observations temper this picture. First, the remaining leakage is concentrated rather than spread out: under DP, a tenth of the records carries roughly 40% of it. Second, the protection DP delivers in practice is uneven: within its worst-case guarantee, the noise removes more of the measured leakage from random records than from high-risk ones---and a merged-pool audit that scores both record types against shared negatives confirms this at the record level. Third, \emph{which} records leak proves to be a property of the release mechanism rather than of the record alone, so record-level risk cannot be assessed independently of the release.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑