为化学数据建模设计了隐私保护的偏最小二乘回归方法。
$(ε, δ)$-Differentially Private Partial Least Squares Regression
- 在PLS关键组件中加入高斯噪声,实现$(ε, δ)$-差分隐私
- 在$ε=1$时仍保持良好预测精度(RMSEP竞争力强)
- 适合需要保护敏感化学数据的研究者使用
随着数据隐私要求日益严格,基于敏感数据的统计模型广泛应用,数据隐私保护变得至关重要。偏最小二乘(PLS)回归是分析化学中的主流建模工具,但本身不提供隐私保障,使训练数据易受隐私攻击。为此,我们提出$(ε, δ)$-差分隐私的PLS(edPLS)算法,将成熟的高斯噪声添加机制融入PLS流程,确保模型背后数据的隐私性。具体在PLS的四个关键函数输出——权重、得分、X载荷和Y载荷上,根据各函数的全局敏感度,精确校准高斯噪声方差,以控制隐私损失。实验表明,edPLS能有效阻止试图恢复训练数据独特变异源的隐私攻击。在近红外玉米基准数据集上的应用显示,在强隐私设置($ε=1$)下,预测均方根误差(RMSEP)依然具有竞争力,前提是光谱数据经过适当预处理。这些结果凸显edPLS在构建隐私保护多变量校准模型中的实用性,以及对隐私-效用权衡分析的支持。
原文摘要 · Abstract (English)
As data-privacy requirements are becoming increasingly stringent and statistical models based on sensitive data are being deployed and used more routinely, protecting data-privacy becomes pivotal. Partial Least Squares (PLS) regression is the premier tool for building such models in analytical chemistry, yet it does not inherently provide privacy guarantees, leaving sensitive (training) data vulnerable to privacy attacks. To address this gap, we propose an $(ε, δ)$-differentially private PLS (edPLS) algorithm, which integrates well-studied and theoretically motivated Gaussian noise-adding mechanisms into the PLS algorithm to ensure the privacy of the data underlying the model. Our approach involves adding carefully calibrated Gaussian noise to the outputs of four key functions in the PLS algorithm: the weights, scores, $X$-loadings, and $Y$-loadings. The noise variance is determined based on the global sensitivity of each function, ensuring that the privacy loss is controlled according to the $(ε, δ)$-differential privacy framework. Specifically, we derive the sensitivity bounds for each function and use these bounds to calibrate the noise added to the model components. Experimental results demonstrate that edPLS effectively renders privacy attacks, aimed at recovering unique sources of variability in the training data, ineffective. Application of edPLS to the NIR corn benchmark dataset shows that the root mean squared error of prediction (RMSEP) remains competitive even at strong privacy levels (i.e., $ε=1$), given proper pre-processing of the corresponding spectra. These findings highlight the practical utility of edPLS in creating privacy-preserving multivariate calibrations and for the analysis of their privacy-utility trade-offs.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。