保护用户隐私的前提下,实现对反事实解释的精准检索。
Private Counterfactual Retrieval
- 基于私有信息检索技术,确保用户查询时无隐私泄露。
- 可精确获取最近邻反事实解释,且用户隐私达到信息论安全。
- 支持用户偏好调整,提升解释的可操作性,适合高风险场景使用。
在高风险应用中,黑箱机器学习模型的透明性和可解释性至关重要。提供反事实解释是满足这一需求的重要方式,但也会威胁到提供解释的机构及请求解释的用户的隐私。本文提出多种受私有信息检索(PIR)启发的方案,确保在检索反事实解释时保护用户隐私。所提方案能从已接受点数据库中精确检索最近邻反事实解释,同时实现用户隐私的信息论完全保护。尽管用户隐私得到保障,数据库仍存在不可避免的信息泄漏,我们通过互信息度量进行了量化。此外,提出策略以降低数据库泄漏,提升数据库隐私水平。方案进一步扩展以融入用户对属性变换的偏好,使解释更具可操作性。由于方案依赖有限域运算,我们在真实数据集上进行了实证验证,分析了准确率与有限域大小之间的权衡。最后,数值结果支持理论分析,并对比了不同方案的数据库泄漏程度。
原文摘要 · Abstract (English)
Transparency and explainability are two extremely important aspects to be considered when employing black-box machine learning models in high-stake applications. Providing counterfactual explanations is one way of fulfilling this requirement. However, this also poses a threat to the privacy of both the institution that is providing the explanation as well as the user who is requesting it. In this work, we propose multiple schemes inspired by private information retrieval (PIR) techniques which ensure the \emph{user's privacy} when retrieving counterfactual explanations. We present a scheme which retrieves the \emph{exact} nearest neighbor counterfactual explanation from a database of accepted points while achieving perfect (information-theoretic) privacy for the user. While the scheme achieves perfect privacy for the user, some leakage on the database is inevitable which we quantify using a mutual information based metric. Furthermore, we propose strategies to reduce this leakage to achieve an advanced degree of database privacy. We extend these schemes to incorporate user's preference on transforming their attributes, so that a more actionable explanation can be received. Since our schemes rely on finite field arithmetic, we empirically validate our schemes on real datasets to understand the trade-off between the accuracy and the finite field sizes. Finally, we present numerical results to support our theoretical findings, and compare the database leakage of the proposed schemes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。