发表机构
CWI Amsterdam; Vrije Universiteit Amsterdam(阿姆斯特丹CWI; 阿姆斯特丹自由大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对随机分配DP-SGD,提出闭式公式限制成员推断攻击准确性,噪声校准优于现有方法,计算快速且可解释。
AI 中文摘要
DP-SGD通过对裁剪梯度添加高斯噪声来保护训练数据。噪声量通常通过在搜索过程中运行数值隐私会计来选择。我们研究具有随机分配的DP-SGD,其中每个epoch在随机选择的步骤中使用每条记录一次。对于这种设置,我们给出一个单行公式,用于限制对训练模型进行的每次成员推断攻击(MIA)的准确性。每个epoch有M步,共E个epoch,噪声乘数为σ,且成员和非成员先验概率相等时,攻击准确性至多为1/2+1/4√((1+(e^(1/σ^2)-1)/M)^E-1)。该公式源于高斯分布与支配随机分配的高斯混合之间的卡方散度。它可解释性强,且计算σ仅需约一微秒。在适用情况下,我们的公式所需噪声至多约为最先进的闭式界所需噪声的一半。为衡量该界的紧密程度,我们还推导了这两种分布攻击准确性的精确表达式,并进行了数值评估。根据此精确表达式进行校准,在主实验中所需噪声比公式少13.0%至20.2%,且由于它是精确的,仅知道M、E和σ的会计无法认证更小的σ。在训练中,由此得到的σ优于公式,并在测试准确率上与已发表的会计相匹配。它在数秒内找到,并在数分钟内得到认证,而我们使用该会计运行的每次搜索要么耗时更长,要么返回至少多0.62%的噪声。我们证明训练模型上的MIA保持在界之下。
英文摘要
DP-SGD protects training data by adding Gaussian noise to clipped gradients. The amount of noise is usually chosen by running a numerical privacy accountant inside a search. We study DP-SGD with random allocation, where each epoch uses every record once, at a randomly chosen step. For this setting we give a one-line formula that bounds the accuracy of every membership inference attack (MIA) on the trained model. With $M$ steps per epoch, $E$ epochs and noise multiplier $σ$, and with membership and non-membership equally likely a priori, the attack accuracy is at most $\frac12+\frac14\sqrt{(1+(e^{1/σ^2}-1)/M)^E-1}$. The formula comes from the chi-square divergence between a Gaussian distribution and a Gaussian mixture that dominates random allocation. It is interpretable and gives $σ$ in about a microsecond. Where applicable, our formula needs at most about half the noise of the state-of-the-art closed-form bound. To measure how close the bound is, we also derive an exact expression for the attack accuracy of these two distributions and evaluate it numerically. Calibrating to this exact expression requires $13.0\%$ to $20.2\%$ less noise than the formula in our main experiments, and since it is exact, no accountant that knows only $M$, $E$ and $σ$ can certify a smaller $σ$. In training, the resulting $σ$ outperforms the formula and matches a published accountant in test accuracy. It is found in seconds and certified in minutes, whereas every search we ran with that accountant took longer or returned at least $0.62\%$ more noise. We show that MIAs on the trained models stay below the bound.