arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

从嵌入中实现分布式且私密的文本数据合成

Distributed and Private Textual Data Synthesis from Embeddings

Ergute Bao, Hongyan Chang, Ali Shahin Shamsabadi, Ting Yu, Xiaokui Xiao

arXiv 2609.10104首次发表:更新:

发表机构

Inria; MBZUAI; Brave Software; National University of Singapore(法国国家信息与自动化研究所; 穆罕默德·本·扎耶德人工智能大学; Brave软件公司; 新加坡国立大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对分布式场景下无可信策展人的差分隐私文本合成难题,提出DP与密码学协同设计,通过一次性DP摘要与安全协议实现轻量级参与,在四个基准上达到集中式方法的效用。

AI 中文摘要

我们重新审视了在分布式用户的现实场景中的差分隐私(DP)文本合成问题,其中隐私顾虑排除了能够访问原始用户文本的可信策展人。现有的DP文本合成流程是为可信的集中式策展人设计的,由于不切实际的信任和访问假设,通常无法在分布式环境中部署;当被简单改编时,它们需要用户反复、高度同步的参与,并产生显著的开销。为了解决这一差距,我们提出了一种DP与密码学协同设计的文本数据合成方法,该方法不需要可信策展人,且仅需要轻量级的用户参与。我们的方法包含两个优化组件。首先,我们设计了一种分布式友好的DP合成算法,该算法在嵌入空间中发布一次性的DP摘要:它识别频繁的语义区域并发布其DP质心,从而实现免训练、非迭代的离线文本合成。我们进一步引入了语义支持保护,确保发布的摘要避开不频繁文本的语义邻域,从而降低暴露稀有用户数据的风险。其次,我们开发了一种定制的安全协议,该协议在分布式用户数据上实现此算法,在不要求可信策展人的情况下强制执行端到端的DP保证。在四个基准测试上,我们实现了与最先进的集中式DP合成方法相当的效用。

英文摘要

We revisit differentially private (DP) text synthesis in the realistic setting of distributed users, where privacy concerns preclude a trusted curator with access to raw user texts. Existing DP text synthesis pipelines are designed for a trusted, centralized curator and often cannot be deployed in distributed settings due to unrealistic trust and access assumptions; when adapted naively, they require repeated, tightly synchronized user participation and incur significant overhead. To address this gap, we propose a DP--cryptography co-design for textual data synthesis that requires no trusted curator and requires only lightweight user participation. Our approach has two optimized components. First, we design a distributed-friendly DP synthesis algorithm that releases a one-time DP summary in an embedding space: it identifies frequent semantic regions and releases their DP centroids, enabling training-free, non-iterative offline text synthesis. We further introduce semantic support protection, which ensures the released summary avoids semantic neighborhoods of infrequent texts, reducing the risk of exposing rare user data. Second, we develop a custom secure protocol that implements this algorithm over distributed user data, enforcing end-to-end DP guarantees without requiring a trusted curator. On four benchmarks, we achieve utility comparable to the state-of-the-art centralized DP synthesis method.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑