用非渐近高斯差分隐私提升机器学习隐私报告的准确性
Gaussian DP for Reporting Differential Privacy Guarantees in Machine Learning
- 提出用非渐近高斯差分隐私(GDP)替代传统DP报告方式
- 实证显示GDP能几乎无误差地刻画DP-SGD等算法的完整隐私轮廓
- 适合关注隐私保障严谨性的机器学习研究者与开发者
当前机器学习中报告差分隐私(DP)保证的做法,如对DP-SGD仅提供单一(ε, δ)值,常呈现不完整甚至误导的信息。例如,仅知一个(ε, δ)时,标准分析可能暗示存在高精度的训练数据推断攻击,而更细致的分析表明,多数实际机制并不存在此类攻击。本文主张以非渐近高斯差分隐私(GDP)作为通信机器学习中DP保证的主要手段,可避免上述问题。结合两项最新进展:(i) 可计算任意精度的隐私轮廓和f-DP曲线的开源数值会计工具;(ii) 基于决策理论的DP表示度量,我们展示了如何利用数值会计获得非渐近的GDP边界,并证明GDP能以极小误差捕捉DP-SGD及相关算法的完整隐私轮廓。通过分析最先进的大规模图像分类模型及美国十年一次人口普查的TopDown算法,发现GDP在所有情况下均能极好拟合其隐私轮廓。最后讨论该方法的优缺点,并探讨其他哪些隐私机制可受益于GDP。
原文摘要 · Abstract (English)
Current practices for reporting differential privacy (DP) guarantees for machine learning (ML) algorithms such as DP-SGD provide an incomplete and potentially misleading picture. For instance, if only a single $(\varepsilon, δ)$ is known about a mechanism, standard analyses show that there could exist highly accurate inference attacks against training data records, when, upon a more careful analysis, such accurate attacks do not exist for most practical mechanisms. In this position paper, we argue that using _non-asymptotic_ Gaussian Differential Privacy (GDP) as the primary means of communicating DP guarantees in ML avoids these potential downsides. Using two recent developments in the DP literature: (i) open-source numerical accountants capable of computing the privacy profile and $f$-DP curves of DP-SGD to arbitrary accuracy, and (ii) a decision-theoretic metric over DP representations, we show how to provide non-asymptotic bounds on GDP using numerical accountants, and show that GDP can capture the entire privacy profile of DP-SGD and related algorithms with virtually no error, as quantified by the metric. To support our claims, we investigate the privacy profiles of state-of-the-art DP large-scale image classification, and the TopDown algorithm for the U.S. Decennial Census, observing that GDP fits their profiles remarkably well in all cases. We conclude with a discussion on the strengths and weaknesses of this approach, and discuss which other privacy mechanisms could benefit from GDP.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。