arXiv:2411.18746cs.CRcs.IT2024-11被引 1

提出推理阶段隐私保护框架,让用户在使用模型时保障数据安全。

Inference Privacy: Properties and Mechanisms

  • 定义推理隐私概念,提供用户数据在模型使用中的严格保护
  • 设计输入与输出扰动机制,支持用户自定义隐私与性能权衡
  • 适用于对数据隐私敏感的AI应用,如聊天机器人、分类器

在推理阶段保障隐私至关重要,可防止恶意第三方从公开模型的输出中重建用户的私有输入。尽管已有大量关于隐私保护学习的研究(确保训练数据隐私),但尚无系统性框架能保障推理阶段的用户数据隐私。为此,本文提出推理隐私(Inference Privacy, IP)概念,使用户在与模型(如分类器或AI辅助聊天机器人)交互时,获得严格的隐私保证。我们建立了IP的基本性质,并将其与局部差分隐私(LDP)进行对比。随后,提出了两类实现IP的机制:输入扰动和输出扰动,均由用户定制,可灵活调节隐私与效用之间的权衡。通过实验验证了该框架的有效性,并揭示了推理阶段隐私与性能之间的实际权衡关系。

原文摘要 · Abstract (English)

Ensuring privacy during inference stage is crucial to prevent malicious third parties from reconstructing users' private inputs from outputs of public models. Despite a large body of literature on privacy preserving learning (which ensures privacy of training data), there is no existing systematic framework to ensure the privacy of users' data during inference. Motivated by this problem, we introduce the notion of Inference Privacy (IP), which can allow a user to interact with a model (for instance, a classifier, or an AI-assisted chat-bot) while providing a rigorous privacy guarantee for the users' data at inference. We establish fundamental properties of the IP privacy notion and also contrast it with the notion of Local Differential Privacy (LDP). We then present two types of mechanisms for achieving IP: namely, input perturbations and output perturbations which are customizable by the users and can allow them to navigate the trade-off between utility and privacy. We also demonstrate the usefulness of our framework via experiments and highlight the resulting trade-offs between utility and privacy during inference.

推理隐私差分隐私数据安全模型应用

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。