arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

超越单一扰动:多属性度量差分隐私的异构机制设计

Beyond Monolithic Perturbation: Heterogeneous Mechanism Design for Multi-Attribute Metric Differential Privacy

Ruiyao Liu, Michael Oluwole, Chenxi Qiu

arXiv 2610.05561首次发表:更新:

发表机构

University of North Texas(北德克萨斯大学)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

针对多属性记录的异构性,提出依赖感知的异构数据扰动框架DepHDP,通过属性分组和混合机制选择,在全局ℓ_p度量mDP约束下联合优化隐私预算与机制设计,以更低计算成本改善隐私-效用权衡。

AI 中文摘要

多属性用户记录本质上是异构的,通常包含连续、分类和二元属性,并且经常表现出强烈的跨属性依赖关系。为此类记录设计高实用性的度量差分隐私(mDP)机制具有挑战性。简单的预定义机制(如基于距离的噪声)可能与特定任务的效用损失对齐不佳,而完全基于优化的机制对于多属性记录而言可能计算上不可行。我们提出了依赖感知的异构数据扰动(DepHDP)框架,用于多属性mDP,该框架将依赖感知的属性分组与异构扰动设计相结合。DepHDP并非采用一刀切的机制,而是为每个属性或属性组选择合适的扰动策略,在高效的预定义机制(如拉普拉斯机制或指数机制)与基于优化的设计之间进行选择。该选择由领域大小和预定义噪声充分性准则共同指导,该准则量化了任务引起的效用损失是否能由扰动幅度很好地解释。为了支持可扩展的端到端优化,DepHDP通过采样和轻量级代理建模来估计组级效用损失,并在全局ℓ_p度量mDP约束下联合优化隐私预算分配和组级机制设计。在三个案例研究中,DepHDP在评估领域上以低于全记录OPT的计算成本,相比均匀基线改善了隐私-效用权衡。

英文摘要

Multi-attribute user records are inherently heterogeneous, often combining continuous, categorical, and binary attributes, and they frequently exhibit strong cross-attribute dependencies. Designing high-utility metric differential privacy (mDP) mechanisms for such records is challenging. Simple predefined mechanisms, such as distance-based noise, may be poorly aligned with task-specific utility loss, whereas fully optimization-based mechanisms can be computationally prohibitive for multi-attribute records. We propose Dependency-aware Heterogeneous Data Perturbation (DepHDP)}, a framework for multi-attribute mDP that combines dependency-aware attribute grouping with heterogeneous perturbation design. Rather than applying a one-size-fits-all mechanism, DepHDP selects an appropriate perturbation strategy for each attribute or attribute group, choosing between efficient predefined mechanisms, such as Laplace or Exponential mechanisms, and optimization-based designs. This selection is guided by both domain size and a predefined-noise adequacy criterion, which quantifies whether task-induced utility loss can be well explained by perturbation magnitude. To support scalable end-to-end optimization, DepHDP estimates group-level utility loss through sampling and lightweight surrogate modeling, and jointly optimizes privacy-budget allocation and group-wise mechanism design under a global $\ell_p$-metric mDP constraint. Across three case studies, DepHDP improves privacy--utility trade-offs over uniform baselines at lower computational cost than full-record OPT on evaluated domains.

CommentsIEEE Symposium on Security and Privacy (S&P), 2027

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑