用梯度特征实时检测模型训练中的隐私泄露风险。
Real-Time Privacy Risk Measurement with Privacy Tokens for Gradient Leakage
- 从训练梯度中提取隐私令牌,捕捉数据泄露特征。
- 结合互信息量化泄漏程度,实现全程实时评估。
- 无需攻击模拟,适合高敏感场景的模型部署监控。
深度学习模型在隐私敏感领域的广泛应用加剧了训练过程中梯度泄露带来的隐私风险。现有隐私评估主要依赖训练后攻击模拟,但此类方法具有被动性,难以覆盖所有攻击场景,且常基于理想化对抗假设。为此,我们提出隐私令牌概念,直接从训练过程中的私有梯度中提取,融合数据特征以揭示训练数据的隐私泄露程度,实现无需攻击模拟的实时隐私风险测量。同时,采用互信息(Mutual Information, MI)作为鲁棒指标,精确量化训练数据与梯度间的关联性,提供连续、精准的隐私泄露评估。大量实验验证了该框架的有效性,表明隐私令牌与MI在识别和量化隐私风险方面表现优异。这一主动式方法显著提升了隐私监控能力,推动深度学习模型在敏感应用中的安全部署。
原文摘要 · Abstract (English)
The widespread deployment of deep learning models in privacy-sensitive domains has amplified concerns regarding privacy risks, particularly those stemming from gradient leakage during training. Current privacy assessments primarily rely on post-training attack simulations. However, these methods are inherently reactive, unable to encompass all potential attack scenarios, and often based on idealized adversarial assumptions. These limitations underscore the need for proactive approaches to privacy risk assessment during the training process. To address this gap, we propose the concept of privacy tokens, which are derived directly from private gradients during training. Privacy tokens encapsulate gradient features and, when combined with data features, offer valuable insights into the extent of private information leakage from training data, enabling real-time measurement of privacy risks without relying on adversarial attack simulations. Additionally, we employ Mutual Information (MI) as a robust metric to quantify the relationship between training data and gradients, providing precise and continuous assessments of privacy leakage throughout the training process. Extensive experiments validate our framework, demonstrating the effectiveness of privacy tokens and MI in identifying and quantifying privacy risks. This proactive approach marks a significant advancement in privacy monitoring, promoting the safer deployment of deep learning models in sensitive applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。