arXiv:2410.02777cs.CYcs.LG2024-10NeurIPS被引 9

为在线部署的模型提供可验证的公平性证书,兼顾安全与效率。

Secure and Confidential Certificates of Online Fairness

  • 通过在线数据实时验证模型公平性,避免静态测试的局限。
  • 提出OATH协议,零知识证明下实现高效公平性认证。
  • 适合关注模型伦理与合规性的平台开发者和监管方。

黑箱服务模式使机器学习服务提供商能在保护知识产权和客户数据隐私的前提下向用户提供服务。然而,隐私保护使得外部方难以验证模型的关键属性(如公平性)。现有保密公平性评估方法要么因基于静态数据集而可靠性不足,无法应对分布偏移或服务提供方恶意行为;要么因依赖保密加密原语导致计算开销过大,难以扩展。本文提出在线公平性证书,用于验证模型在部署过程中接收的实时数据上的公平性。进一步提出OATH协议,一种可部署、可扩展的零知识证明方案,实现保密的群体公平性认证。该协议利用群体公平性的统计特性,采用类似剪切-选择的机制,在保持安全性的同时显著提升效率,相较基线有明显性能优势。

原文摘要 · Abstract (English)

The black-box service model enables ML service providers to serve clients while keeping their intellectual property and client data confidential. Confidentiality is critical for delivering ML services legally and responsibly, but makes it difficult for outside parties to verify important model properties such as fairness. Existing methods that assess model fairness confidentially lack either (i) reliability because they certify fairness with respect to a static set of data, and therefore fail to guarantee fairness in the presence of distribution shift or service provider malfeasance; and/or (ii) scalability due to the computational overhead of confidentiality-preserving cryptographic primitives. We address these problems by introducing online fairness certificates, which verify that a model is fair with respect to data received by the service provider online during deployment. We then present OATH, a deployably efficient and scalable zero-knowledge proof protocol for confidential online group fairness certification. OATH exploits statistical properties of group fairness via a cut-and-choose style protocol, enabling scalability improvements over baselines.

公平性零知识证明模型安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。