用扩散模型从加噪梯度中重建隐私图像,揭示差分隐私噪声的攻击影响。
Gradient-Guided Conditional Diffusion Models for Private Image Reconstruction: Analyzing Adversarial Impacts of Differential Privacy and Denoising
- 基于梯度引导的条件扩散模型,无需先验知识即可重建图像。
- 即使在微小差分隐私噪声下,仍能高质量还原图像。
- 理论分析揭示噪声强度与模型架构对重建能力的影响,适合隐私审计研究者。
我们研究了用于重建隐私图像的梯度引导条件扩散模型构建,重点分析差分隐私噪声与扩散模型去噪能力之间的对抗性关系。现有基于梯度的重建方法因计算复杂度高和需先验知识,在高分辨率图像上表现不佳。为此,我们提出两种新方法,仅需对扩散模型生成过程做最小修改,且无需先验知识。该方法利用扩散模型强大的图像生成能力,从随机噪声出发重建图像,即便梯度中已添加少量差分隐私噪声。我们还对差分隐私噪声对重建质量的影响进行了全面理论分析,揭示了噪声大小、被攻击模型架构与攻击者重建能力之间的关系。大量实验验证了所提方法的有效性及理论结论的准确性,为使用条件扩散模型进行隐私风险审计提供了新方向。
原文摘要 · Abstract (English)
We investigate the construction of gradient-guided conditional diffusion models for reconstructing private images, focusing on the adversarial interplay between differential privacy noise and the denoising capabilities of diffusion models. While current gradient-based reconstruction methods struggle with high-resolution images due to computational complexity and prior knowledge requirements, we propose two novel methods that require minimal modifications to the diffusion model's generation process and eliminate the need for prior knowledge. Our approach leverages the strong image generation capabilities of diffusion models to reconstruct private images starting from randomly generated noise, even when a small amount of differentially private noise has been added to the gradients. We also conduct a comprehensive theoretical analysis of the impact of differential privacy noise on the quality of reconstructed images, revealing the relationship among noise magnitude, the architecture of attacked models, and the attacker's reconstruction capability. Additionally, extensive experiments validate the effectiveness of our proposed methods and the accuracy of our theoretical findings, suggesting new directions for privacy risk auditing using conditional diffusion models.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。