arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

保形隐私审计:具有统计保证的校准重识别攻击

Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees

Shuo Huang, Gholamreza Haffari, Xingliang Yuan, Ting Yu, Lizhen Qu

arXiv 2609.21340首次发表:更新:

发表机构

Monash University; The University of Melbourne; Mohamed bin Zayed University of Artificial Intelligence(莫纳什大学; 墨尔本大学; 穆罕默德·本·扎耶德人工智能大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出保形隐私审计(CPA),一种无分布校准框架,为每个发布文档提供针对LLM赋能攻击者的重识别风险统计证书,通过保形模糊集实现校准覆盖,并揭示不同配置下的可识别性变化。

AI 中文摘要

来自已发布文本的经验身份泄露日益由结合大型语言模型(LLM)与辅助知识以将文档链接到个人的攻击者驱动。现有审计通常报告特定攻击流程的成功率,但缺乏有限样本统计保证,而诸如差分隐私之类的训练时保护难以转化为针对单个自然语言文档的发布时决策。我们引入了保形隐私审计(CPA),一种无分布校准框架,为每个发布的文档针对LLM赋能的对手提供重识别风险的统计证书。CPA输出一个保形模糊候选身份集,在可交换性假设下,该集合以用户选择的置信度保证包含真实身份,同时提供一个由集合大小导出的可解释泄漏代理。CPA支持基于logit访问和仅采样攻击者,从而在统一框架中实现对开源模型和专有API模型的审计。在多个发布基准和攻击者配置中,CPA实现了校准覆盖,并揭示了随着辅助知识、LLM增强和发布机制变化,认证可识别性的显著变化,为跨攻击者配置、数据集和发布机制报告和比较发布时链接风险提供了统计基础。

英文摘要

Empirical identity leakage from released text is increasingly driven by attackers that combine large language models (LLMs) with auxiliary knowledge to link documents to individuals. Existing audits typically report success rates for specific attack pipelines but lack finite-sample statistical guarantees, while training-time protections such as differential privacy are difficult to translate into release-time decisions for individual natural-language documents. We introduce Conformal Privacy Auditing(CPA), a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries. CPA outputs a conformal ambiguity set of candidate identities that is guaranteed to contain the true identity with user-chosen confidence under exchangeability, together with an interpretable leakage proxy derived from set size. CPA supports both logit-access and sampling-only attackers, enabling audits of open-source models and proprietary API models in a unified framework. Across multiple release benchmarks and attacker configurations, CPA achieves calibrated coverage and reveals sharp shifts in certified identifiability as auxiliary knowledge, LLM augmentation, and release mechanisms vary, providing a statistically grounded basis for reporting and comparing release-time linkage risk across attacker configurations, datasets, and release mechanisms alike.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑