比较不同隐私保护机制在机器学习重建攻击下的有效性
Comparing privacy notions for protection against reconstruction attacks in machine learning
- 提出两种对比隐私机制的框架:瑞尼差分隐私和贝叶斯容量
- 揭示不同隐私参数ε、δ在联邦学习中的实际意义差异
- 适合关注隐私保护评估与联邦学习安全的研究者
在机器学习领域,重建攻击是主要威胁,甚至在设计用于隐私保护的联邦学习(FL)中也已出现。为应对这些威胁,隐私社区推荐在随机梯度下降算法中使用差分隐私(DP),即DP-SGD。然而,近年来出现了多种DP变体(如度量隐私),由于不同变体中隐私参数ε和δ的含义不一致,导致难以公平比较不同机制。本文建立了一个基础框架,用于比较具有不同隐私保证机制的性能,包括(ε,δ)-DP与度量隐私。我们提供两种对比方法:一是通过瑞尼差分隐私框架实现的(ε,δ)-DP保证;二是通过贝叶斯容量这一指标衡量重建威胁的适用性。
原文摘要 · Abstract (English)
Within the machine learning community, reconstruction attacks are a principal concern and have been identified even in federated learning (FL), which was designed with privacy preservation in mind. In response to these threats, the privacy community recommends the use of differential privacy (DP) in the stochastic gradient descent algorithm, termed DP-SGD. However, the proliferation of variants of DP in recent years\textemdash such as metric privacy\textemdash has made it challenging to conduct a fair comparison between different mechanisms due to the different meanings of the privacy parameters $ε$ and $δ$ across different variants. Thus, interpreting the practical implications of $ε$ and $δ$ in the FL context and amongst variants of DP remains ambiguous. In this paper, we lay a foundational framework for comparing mechanisms with differing notions of privacy guarantees, namely $(ε,δ)$-DP and metric privacy. We provide two foundational means of comparison: firstly, via the well-established $(ε,δ)$-DP guarantees, made possible through the Rényi differential privacy framework; and secondly, via Bayes' capacity, which we identify as an appropriate measure for reconstruction threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。