arXiv:2410.22235cs.LGcs.CR2024-10被引 35

单次运行即可精准评估隐私保护机制的差分隐私水平。

Auditing $f$-Differential Privacy in One Run

  • 利用输入数据的随机性,仅需一次运行目标机制完成审计。
  • 基于假设的f-DP曲线,实现比传统ε,δ更精确的隐私估计。
  • 适合关注隐私泄露风险的开发者与研究者使用。

实证审计已成为发现隐私保护算法实现缺陷的一种手段。然而,现有的审计机制要么计算效率低下,需要多次运行机器学习算法,要么在估算经验隐私时表现欠佳。本文提出一种高效且紧致的审计流程与分析方法,可有效评估机制的隐私性。该方法高效:类似于Steinke、Nasr和Jagielski(2023)的近期工作,其审计过程利用输入数据集中的样本随机性,仅需对目标机制执行一次运行。同时更准确:我们提出一种新分析方法,通过使用机制所假设的f-DP曲线,实现了紧致的经验隐私估计,相比传统的ε,δ差分隐私参数提供了更精确的隐私度量。我们通过该审计流程与分析获得经验隐私,证明了该方法能提供更紧致的隐私估计。

原文摘要 · Abstract (English)

Empirical auditing has emerged as a means of catching some of the flaws in the implementation of privacy-preserving algorithms. Existing auditing mechanisms, however, are either computationally inefficient requiring multiple runs of the machine learning algorithms or suboptimal in calculating an empirical privacy. In this work, we present a tight and efficient auditing procedure and analysis that can effectively assess the privacy of mechanisms. Our approach is efficient; similar to the recent work of Steinke, Nasr, and Jagielski (2023), our auditing procedure leverages the randomness of examples in the input dataset and requires only a single run of the target mechanism. And it is more accurate; we provide a novel analysis that enables us to achieve tight empirical privacy estimates by using the hypothesized $f$-DP curve of the mechanism, which provides a more accurate measure of privacy than the traditional $ε,δ$ differential privacy parameters. We use our auditing procure and analysis to obtain empirical privacy, demonstrating that our auditing procedure delivers tighter privacy estimates.

差分隐私隐私审计f-DP

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。