提出新型截断拉普拉斯机制,实现高隐私下的语言模型低损耗嵌入
Private Language Models via Truncated Laplacian Mechanism
- 引入高维截断拉普拉斯机制,改进传统隐私保护嵌入方法
- 在高隐私设置下,性能下降仅轻微,优于现有方法
- 适合对隐私敏感的NLP应用,如医疗或金融文本处理
自然语言处理中的深度学习模型易受各类隐私攻击。为防止隐私泄露,研究者曾采用词级扰动并依赖嵌入空间中的差分隐私(DP)保障。然而,现有方法在使用拉普拉斯或高斯机制时,于高隐私设置下表现不佳,或退化为较弱的DP松弛形式,削弱了隐私强度。本文提出一种新的私有嵌入方法——高维截断拉普拉斯机制。我们首次将截断拉普拉斯机制从一维推广至高维空间。理论分析表明,该方法方差低于现有私有嵌入方法。在三个数据集上进行的综合实验验证其有效性:即使在高隐私预算下,该方法仅带来轻微效用损失,接近非私有场景表现。
原文摘要 · Abstract (English)
Deep learning models for NLP tasks are prone to variants of privacy attacks. To prevent privacy leakage, researchers have investigated word-level perturbations, relying on the formal guarantees of differential privacy (DP) in the embedding space. However, many existing approaches either achieve unsatisfactory performance in the high privacy regime when using the Laplacian or Gaussian mechanism, or resort to weaker relaxations of DP that are inferior to the canonical DP in terms of privacy strength. This raises the question of whether a new method for private word embedding can be designed to overcome these limitations. In this paper, we propose a novel private embedding method called the high dimensional truncated Laplacian mechanism. Specifically, we introduce a non-trivial extension of the truncated Laplacian mechanism, which was previously only investigated in one-dimensional space cases. Theoretically, we show that our method has a lower variance compared to the previous private word embedding methods. To further validate its effectiveness, we conduct comprehensive experiments on private embedding and downstream tasks using three datasets. Remarkably, even in the high privacy regime, our approach only incurs a slight decrease in utility compared to the non-private scenario.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。