自适应扩散冻结:针对成员推断攻击的隐私保护扩散模型
Adaptive Diffusion Freezing: Privacy-preserving Diffusion Models Against Membership Inference Attacks
浏览论文内容
中文总结 AI 辅助
针对扩散模型成员推断攻击的隐私泄露问题,提出自适应扩散冻结(ADF)框架,通过跨时间步掩码控制数据参与并基于风险感知策略抑制高风险子集,实现隐私、效用与效率的最优权衡。
中文摘要 AI 辅助
扩散模型在多个领域的生成任务中取得了显著成功,然而其训练过程引发了重大的隐私担忧,尤其是在成员推断攻击(MIAs)下。先前关于扩散模型隐私保护的研究未能平衡隐私、效用和效率。为解决这一差距,我们提出了一种新颖的隐私保护扩散模型框架——自适应扩散冻结(ADF),它能够以更好的权衡抵御成员推断攻击。通过利用跨时间步自适应冻结训练,ADF通过掩码矩阵显式控制不同数据子集在扩散时间步上的参与,从而减少过度记忆,并使成员样本与非成员样本之间的模型行为更加均匀。为了构建一个能有效减少成员泄漏而不不必要地损害生成质量的冻结掩码矩阵,我们引入了一种基于预训练的风险感知冻结策略,根据记忆倾向估计MIA风险,并抑制风险较高的子集-时间步对的贡献。在多个数据集上的评估表明,与各种基线相比,ADF提供了有效的防御性能以及最先进的隐私-效用-效率权衡性能。
英文摘要
Diffusion models have achieved remarkable success in generative tasks across various areas, however their training process raises significant privacy concerns, particularly under membership inference attacks (MIAs). Prior studies on privacy-preserving of diffusion models fail to balance privacy, utility, and efficiency. To address this gap, we propose a novel framework of privacy-preserving diffusion models, Adaptive Diffusion Freezing (ADF), which can defend against MIAs with better trade-off. By leveraging cross-timestep adaptive freezing training, ADF explicitly control the participation of different data subsets across diffusion timesteps via a mask matrix, which reduces the over-memorization and leads to more uniform model behaviors between member and nonmember samples. To construct a freezing mask matrix that effectively reduce membership leakage without unnecessarily harming generation quality, we introduce a pretraining-based risk-aware freezing policy to estimate MIA risk based on memorization tendency, and suppress the contribution of the subset-timestep pairs with higher risk. Evaluations on multiple datasets demonstrate that ADF provides effective defense performance as well as state-of-the-art privacy-utility-efficiency trade-off performance compared to various baselines.
发表机构
- Beihang University(北京航空航天大学)
机构由 AI 辅助整理,请以论文原文为准。