arXiv:2503.07199cs.LGcs.CR2025-03NeurIPS被引 8

研究单次运行审计差分隐私的极限,揭示其精度瓶颈并提出改进方法。

How Well Can Differential Privacy Be Audited in One Run?

  • 通过单次训练运行同时干预多个样本,提升审计效率。
  • 发现不同数据元素间的干扰是限制审计精度的关键障碍。
  • 提出新思路降低干扰,适用于真实机器学习模型的隐私审计。

近期的机器学习隐私审计方法通过在单次训练中同时干预多个训练样本,显著提升了计算效率。Steinke 等人(2024)证明了单次运行审计确实对所审计算法的真实隐私参数提供了下界,并给出了令人印象深刻的实验结果。然而,该工作仍留待解决的问题是:单次运行审计究竟能多精确地揭示算法的真实隐私参数?以及这种精度如何依赖于被审计算法本身?本文刻画了单次运行审计所能达到的最大有效性,指出其主要障碍在于不同数据元素可观测效应之间的干扰。我们提出了新的概念性方法以最小化这一障碍,旨在提升真实机器学习算法的单次运行审计性能。

原文摘要 · Abstract (English)

Recent methods for auditing the privacy of machine learning algorithms have improved computational efficiency by simultaneously intervening on multiple training examples in a single training run. Steinke et al. (2024) prove that one-run auditing indeed lower bounds the true privacy parameter of the audited algorithm, and give impressive empirical results. Their work leaves open the question of how precisely one-run auditing can uncover the true privacy parameter of an algorithm, and how that precision depends on the audited algorithm. In this work, we characterize the maximum achievable efficacy of one-run auditing and show that the key barrier to its efficacy is interference between the observable effects of different data elements. We present new conceptual approaches to minimize this barrier, towards improving the performance of one-run auditing of real machine learning algorithms.

差分隐私隐私审计机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。