arXiv:2410.08111cs.LGcs.AI2024-10AAAI被引 6

不重建模型也能高效审计机器学习的鲁棒性与公平性

Active Fourier Auditor for Estimating Distributional Properties of ML Models

  • 通过傅里叶系数设计主动采样策略,无需重建模型
  • 在多个数据集上比基线方法更准确且节省样本
  • 适合关注模型可信性但无法获取模型结构的研究者

随着机器学习模型在现实应用中的广泛部署,验证和审计其属性成为核心问题。本文聚焦于鲁棒性、个体公平性和群体公平性三类属性。现有研究多基于对目标模型的重构进行审计,但本文首次探索无需重构的审计方法。为此,我们提出主动傅里叶审计器(AFA),通过分析模型的傅里叶系数来主动选择查询点,从而估计各类属性。我们推导了AFA估计值的高概率误差界,并给出了审计所需样本量的最坏情况下界。数值实验表明,在多个数据集和模型上,AFA在估计精度和样本效率方面均优于基线方法。

原文摘要 · Abstract (English)

With the pervasive deployment of Machine Learning (ML) models in real-world applications, verifying and auditing properties of ML models have become a central concern. In this work, we focus on three properties: robustness, individual fairness, and group fairness. We discuss two approaches for auditing ML model properties: estimation with and without reconstruction of the target model under audit. Though the first approach is studied in the literature, the second approach remains unexplored. For this purpose, we develop a new framework that quantifies different properties in terms of the Fourier coefficients of the ML model under audit but does not parametrically reconstruct it. We propose the Active Fourier Auditor (AFA), which queries sample points according to the Fourier coefficients of the ML model, and further estimates the properties. We derive high probability error bounds on AFA's estimates, along with the worst-case lower bounds on the sample complexity to audit them. Numerically we demonstrate on multiple datasets and models that AFA is more accurate and sample-efficient to estimate the properties of interest than the baselines.

模型审计公平性傅里叶分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。