平衡高风险场景下的隐私与可解释性,提出协同实现方案
Reconciling Privacy and Explainability in High-Stakes: A Systematic Inquiry
- 采用差分隐私保护数据隐私,结合后验解释器进行模型审计
- 发现差分隐私会削弱解释器的稳定性与可信度,影响解释有效性
- 适用于医疗、金融等高风险领域,需兼顾隐私与决策透明
深度学习在科学领域的广泛应用重塑了高风险决策流程,亟需同时满足隐私权(RTP)与解释权(RTE)的严格规范。本文聚焦差分隐私(DP)作为当前主流隐私保护机制,以及独立于训练过程的后验解释器作为模型审计工具,系统研究二者间的内在交互关系。重点探讨在差分隐私约束下如何评估解释器的有效性,并揭示其对解释结果稳定性和可信度的负面影响。最后,基于一个广泛应用的典型案例,提出一套工业级软件流水线,实现隐私与可解释性的协同保障。
原文摘要 · Abstract (English)
Deep learning's preponderance across scientific domains has reshaped high-stakes decision-making, making it essential to follow rigorous operational frameworks that include both Right-to-Privacy (RTP) and Right-to-Explanation (RTE). This paper examines the complexities of combining these two requirements. For RTP, we focus on `Differential privacy` (DP), which is considered the current gold standard for privacy-preserving machine learning due to its strong quantitative guarantee of privacy. For RTE, we focus on post-hoc explainers: they are the go-to option for model auditing as they operate independently of model training. We formally investigate DP models and various commonly-used post-hoc explainers: how to evaluate these explainers subject to RTP, and analyze the intrinsic interactions between DP models and these explainers. Furthermore, our work throws light on how RTP and RTE can be effectively combined in high-stakes applications. Our study concludes by outlining an industrial software pipeline, with the example of a wildly used use-case, that respects both RTP and RTE requirements.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。