保护用户隐私,实现不可变特征下的反事实样本精准检索
Private Counterfactual Retrieval With Immutable Features
- 基于私有信息检索技术,设计两类隐私保护反事实检索方案
- 确保用户特征、不可变集及检索结果对机构完全不可知
- 适用于需保护敏感数据的公平决策系统,如贷款审批
在分类任务中,反事实解释可提供使输入被划分为理想类别所需的最小修改。本文研究在强制某些特征不可更改(即不可变)的前提下,从已接受样本数据库中私密地检索最接近的反事实样本问题。申请者(用户)的特征向量被机器学习模型拒绝后,希望在不改变其隐私子集特征的情况下,从数据库中找到最接近的样本,同时确保其特征向量、不可变集及最终检索出的反事实索引对机构在信息论上保持私密。我们将此问题称为不可变私有反事实检索(I-PCR),是PCR问题在更实际场景下的推广。本文提出两种I-PCR方案,利用私有信息检索(PIR)技术,并刻画其通信开销。此外,量化了用户对数据库所获信息量,并对两种方案进行比较。
原文摘要 · Abstract (English)
In a classification task, counterfactual explanations provide the minimum change needed for an input to be classified into a favorable class. We consider the problem of privately retrieving the exact closest counterfactual from a database of accepted samples while enforcing that certain features of the input sample cannot be changed, i.e., they are \emph{immutable}. An applicant (user) whose feature vector is rejected by a machine learning model wants to retrieve the sample closest to them in the database without altering a private subset of their features, which constitutes the immutable set. While doing this, the user should keep their feature vector, immutable set and the resulting counterfactual index information-theoretically private from the institution. We refer to this as immutable private counterfactual retrieval (I-PCR) problem which generalizes PCR to a more practical setting. In this paper, we propose two I-PCR schemes by leveraging techniques from private information retrieval (PIR) and characterize their communication costs. Further, we quantify the information that the user learns about the database and compare it for the proposed schemes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。