arXiv:2503.12045stat.MEcs.CR2025-03

提出黑箱环境下审计差分隐私的新方法,可严格控制误报率。

Auditing Differential Privacy in the Black-Box Setting

  • 基于符合性推断构建审计机制,无需强假设
  • 在有限样本下可构造隐私权衡函数的置信区间
  • 在单调似然比假设下能同时控制两类错误

本文提出一种全新的理论框架,用于在黑箱设置下审计差分隐私(DP)。利用 $f$-差分隐私概念,明确定义了第一类和第二类错误,并提出基于符合性推断的审计机制。该方法在最少假设下稳健控制第一类错误率。此外,我们建立了根本性不可能结果,证明在无额外假设下无法同时控制两类错误。但在单调似然比(MLR)假设下,审计机制能有效控制两类错误。我们还将方法扩展至有限样本情形,构建了隐私权衡函数的有效置信带。

原文摘要 · Abstract (English)

This paper introduces a novel theoretical framework for auditing differential privacy (DP) in a black-box setting. Leveraging the concept of $f$-differential privacy, we explicitly define type I and type II errors and propose an auditing mechanism based on conformal inference. Our approach robustly controls the type I error rate under minimal assumptions. Furthermore, we establish a fundamental impossibility result, demonstrating the inherent difficulty of simultaneously controlling both type I and type II errors without additional assumptions. Nevertheless, under a monotone likelihood ratio (MLR) assumption, our auditing mechanism effectively controls both errors. We also extend our method to construct valid confidence bands for the trade-off function in the finite-sample regime.

差分隐私统计审计黑箱测试

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。