arXiv:2504.16683cs.LGstat.ML2025-04被引 1

用马尔可夫链蒙特卡洛方法更精准估算差分隐私水平。

MCMC for Bayesian estimation of Differential Privacy from Membership Inference Attacks

  • 基于多源成员推断攻击证据,通过MCMC联合估计隐私参数与攻击强度。
  • 不假设最坏情况攻击,给出完整后验分布而非仅可信区间。
  • 适合关注隐私分析严谨性的研究人员,尤其在真实场景下评估模型隐私。

我们提出一种新的贝叶斯框架用于差分隐私的估计,整合了多个成员推断攻击(MIA)的证据。通过名为 MCMC-DP-Est 的马尔可夫链蒙特卡洛算法进行贝叶斯推断,可获得隐私参数的完整后验分布(而不仅是可信区间)。该方法不依赖于隐私审计总是使用最强攻击和最坏数据集-查询点组合这一通常不现实的假设。相反,MCMC-DP-Est 联合估计所用 MIA 的强度与训练算法的隐私水平,实现更保守的隐私分析。此外,我们还提出一种经济高效的 MIA 性能测量生成方式,供 MCMC 方法使用。通过人工数据和真实数据的数值实验展示了该方法的应用效果。

原文摘要 · Abstract (English)

We propose a new framework for Bayesian estimation of differential privacy, incorporating evidence from multiple membership inference attacks (MIA). Bayesian estimation is carried out via a Markov chain Monte Carlo (MCMC) algorithm, named MCMC-DP-Est, which provides an estimate of the full posterior distribution of the privacy parameter (e.g., instead of just credible intervals). Critically, the proposed method does not assume that privacy auditing is performed with the most powerful attack on the worst-case (dataset, challenge point) pair, which is typically unrealistic. Instead, MCMC-DP-Est jointly estimates the strengths of MIAs used and the privacy of the training algorithm, yielding a more cautious privacy analysis. We also present an economical way to generate measurements for the performance of an MIA that is to be used by the MCMC method to estimate privacy. We present the use of the methods with numerical examples with both artificial and real data.

差分隐私贝叶斯估计成员推断攻击MCMC

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。