arXiv:2504.18497cs.CRcs.AI2025-04

提出新攻击方法DeSIA,能从少量公开统计值中精准推断个人属性。

DeSIA: Attribute Inference Attacks Against Limited Fixed Aggregate Statistics

  • 基于统计聚合值设计新型属性推理攻击框架
  • 在真实数据集上实现0.14真阳性率、千分之一假阳性率
  • 适用于不可验证属性及不同噪声水平,适合隐私评估者使用

经验性推理攻击是评估实际数据发布机制隐私风险的常用方法。尽管已有大量针对机器学习模型或合成数据的攻击研究,但针对有限固定聚合统计信息的攻击方法仍不充分,尤其当仅释放少量统计值时。本文提出一种针对固定聚合统计的推理攻击框架,并构建名为DeSIA的属性推理攻击。在美国家庭普查PPMF数据集上验证,DeSIA显著优于基于重构的攻击方法。具体而言,其在假阳性率为10⁻³时达到0.14的真阳性率,有效识别出脆弱用户。进一步实验表明,该方法在无法验证属性的用户、不同聚合统计数量及噪声水平下均表现良好。通过广泛的消融分析,还证明DeSIA可成功适配成员推理任务。结果表明,仅依赖聚合不足以保障隐私,即使释放少量统计值亦需正式隐私机制与测试。

原文摘要 · Abstract (English)

Empirical inference attacks are a popular approach for evaluating the privacy risk of data release mechanisms in practice. While an active attack literature exists to evaluate machine learning models or synthetic data release, we currently lack comparable methods for fixed aggregate statistics, in particular when only a limited number of statistics are released. We here propose an inference attack framework against fixed aggregate statistics and an attribute inference attack called DeSIA. We instantiate DeSIA against the U.S. Census PPMF dataset and show it to strongly outperform reconstruction-based attacks. In particular, we show DeSIA to be highly effective at identifying vulnerable users, achieving a true positive rate of 0.14 at a false positive rate of $10^{-3}$. We then show DeSIA to perform well against users whose attributes cannot be verified and when varying the number of aggregate statistics and level of noise addition. We also perform an extensive ablation study of DeSIA and show how DeSIA can be successfully adapted to the membership inference task. Overall, our results show that aggregation alone is not sufficient to protect privacy, even when a relatively small number of aggregates are being released, and emphasize the need for formal privacy mechanisms and testing before aggregate statistics are released.

隐私攻击属性推理统计披露数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。