单次运行即可精准评估隐私保护机制的差分隐私水平。
Auditing $f$-Differential Privacy in One Run
- 利用输入数据的随机性,仅需一次运行目标机制完成审计。
- 基于假设的f-DP曲线,实现比传统ε,δ更精确的隐私估计。
- 适合关注隐私泄露风险的开发者与研究者使用。
实证审计已成为发现隐私保护算法实现缺陷的一种手段。然而,现有的审计机制要么计算效率低下,需要多次运行机器学习算法,要么在估算经验隐私时表现欠佳。本文提出一种高效且紧致的审计流程与分析方法,可有效评估机制的隐私性。该方法高效:类似于Steinke、Nasr和Jagielski(2023)的近期工作,其审计过程利用输入数据集中的样本随机性,仅需对目标机制执行一次运行。同时更准确:我们提出一种新分析方法,通过使用机制所假设的f-DP曲线,实现了紧致的经验隐私估计,相比传统的ε,δ差分隐私参数提供了更精确的隐私度量。我们通过该审计流程与分析获得经验隐私,证明了该方法能提供更紧致的隐私估计。
原文摘要 · Abstract (English)
Empirical auditing has emerged as a means of catching some of the flaws in the implementation of privacy-preserving algorithms. Existing auditing mechanisms, however, are either computationally inefficient requiring multiple runs of the machine learning algorithms or suboptimal in calculating an empirical privacy. In this work, we present a tight and efficient auditing procedure and analysis that can effectively assess the privacy of mechanisms. Our approach is efficient; similar to the recent work of Steinke, Nasr, and Jagielski (2023), our auditing procedure leverages the randomness of examples in the input dataset and requires only a single run of the target mechanism. And it is more accurate; we provide a novel analysis that enables us to achieve tight empirical privacy estimates by using the hypothesized $f$-DP curve of the mechanism, which provides a more accurate measure of privacy than the traditional $ε,δ$ differential privacy parameters. We use our auditing procure and analysis to obtain empirical privacy, demonstrating that our auditing procedure delivers tighter privacy estimates.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。