发表机构
Meta Platforms, Inc.(Meta平台公司)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本研究通过协议感知审计,在私有进化中引入金丝雀探针,评估八种攻击,发现自然文本攻击远低于理论DP界限,而随机数攻击更接近隐私上限,量化了最坏情况隐私与实际泄漏的差距。
AI 中文摘要
私有进化(PE)在联邦设置中生成高保真合成数据,而不会暴露用户的原始数据。它将裁剪后的用户投票聚合到共享候选银行上的差分隐私直方图中,噪声根据最坏情况下的用户贡献进行校准。然而,目前尚不清楚攻击者是否能在遵循PE协议的同时实现这种最坏情况下的隐私损失。我们引入了一种协议感知的经验审计,其中服务器承诺使用单个共享候选银行,并将其约1%的条目替换为来自已知、非私有金丝雀的探针。我们评估了八种攻击,包括未更改银行的基线、精确副本、合理释义和高熵合成随机数。在Yelp和Sentiment140上的实验表明,自然文本攻击仍远低于理论DP界限,而基于随机数的攻击产生了明显更强的界限,并最接近机制的隐私上限。这些结果量化了形式上的最坏情况隐私与通过协议有效的候选银行操纵可实现的泄漏之间的差距。
英文摘要
Private Evolution (PE) generates high-fidelity synthetic data in federated settings without exposing users' raw data. It aggregates clipped user votes over a shared candidate bank into a differentially private histogram, with noise calibrated to the worst-case user contribution. However, it is unclear whether an adversary can realize this worst-case privacy loss while following the PE protocol. We introduce a protocol-aware empirical audit in which the server commits to a single shared candidate bank and replaces roughly 1% of its entries with probes derived from a known, non-private canary. We evaluate eight attacks, including an unchanged-bank baseline, exact copies, plausible paraphrases, and high-entropy synthetic nonces. Experiments on Yelp and Sentiment140 show that natural-text attacks remain substantially below the theoretical DP bound, while nonce-based attacks yield considerably stronger bounds and come closest to the mechanism's privacy ceiling. These results quantify the gap between formal worst-case privacy and leakage achievable through protocol-valid candidate-bank manipulation.
Comments14 pages