arXiv:2503.11850cs.CRcs.DS2025-03ICML

保护联邦设备的隐私数据,防止本地被入侵时泄露信息。

Local Pan-Privacy for Federated Analytics

  • 在本地设备上实现抗多次突袭的隐私保护机制
  • 证明传统方法无法同时保证隐私与数据可用性
  • 用标准密码学技术实现可扩展的隐私方案

Pan-privacy 由 Dwork 等人提出,旨在设计一种即使系统内部状态被入侵仍能保持隐私特性的分析系统。受联邦遥测应用启发,我们研究本地 pan-privacy,即在对本地状态进行反复未预告入侵的情况下仍需维持隐私。本文关注联邦系统中事件计数的监控问题,要求本地设备上的事件发生情况即使对设备上的入侵者也应隐藏。我们证明,在合理约束下,提供信息论意义上的差分隐私(under intrusion)与收集遥测信息的目标不相容。随后,我们展示可通过标准密码学原语以可扩展方式解决该问题。

原文摘要 · Abstract (English)

Pan-privacy was proposed by Dwork et al. as an approach to designing a private analytics system that retains its privacy properties in the face of intrusions that expose the system's internal state. Motivated by federated telemetry applications, we study local pan-privacy, where privacy should be retained under repeated unannounced intrusions on the local state. We consider the problem of monitoring the count of an event in a federated system, where event occurrences on a local device should be hidden even from an intruder on that device. We show that under reasonable constraints, the goal of providing information-theoretic differential privacy under intrusion is incompatible with collecting telemetry information. We then show that this problem can be solved in a scalable way using standard cryptographic primitives.

联邦学习隐私保护密码学差分隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。