arXiv:2412.11066cs.LGcs.CR2024-12AAAI被引 6

用信息论方法学习既抗攻击又保隐私的模型表示。

Learning Robust and Privacy-Preserving Representations via Information Theory

  • 基于信息论设计表示学习框架,统一防御对抗样本和属性推断攻击。
  • 揭示了鲁棒性与隐私之间存在不可调和的权衡关系。
  • 适用于需要同时保障安全与隐私的高敏感场景如医疗数据建模。

机器学习模型易受安全攻击(如对抗样本)和隐私攻击(如私有属性推断)的影响。本文首次尝试同时缓解这两类威胁,并保持任务性能。我们提出一种基于信息论的表示学习框架,旨在学习对对抗样本和属性推断攻击均具备鲁棒性的特征表示。在该框架下,我们推导出若干新理论结果,例如:对抗鲁棒性/任务效用与属性隐私之间存在内在权衡,且可保证对属性推断攻击者的隐私泄露上限。

原文摘要 · Abstract (English)

Machine learning models are vulnerable to both security attacks (e.g., adversarial examples) and privacy attacks (e.g., private attribute inference). We take the first step to mitigate both the security and privacy attacks, and maintain task utility as well. Particularly, we propose an information-theoretic framework to achieve the goals through the lens of representation learning, i.e., learning representations that are robust to both adversarial examples and attribute inference adversaries. We also derive novel theoretical results under our framework, e.g., the inherent trade-off between adversarial robustness/utility and attribute privacy, and guaranteed attribute privacy leakage against attribute inference adversaries.

信息论隐私保护鲁棒学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。