差分隐私保护个人数据,却让集体改写AI行为变得更难。
Crowding Out The Noise: Algorithmic Collective Action Under Differential Privacy
- 用差分隐私训练模型会削弱用户集体改数据的影响
- 集体规模越大、隐私参数越严,影响效果越弱
- 适合关注隐私与集体影响力的学者和政策制定者
AI融入日常生活引发广泛关注,也带来算法危害和不平等加剧的担忧。本文探讨普通用户通过主动修改共享数据来影响AI学习过程的‘算法集体行动’,如何与企业采用的差分隐私技术相互作用。研究聚焦于差分隐私随机梯度下降(DP-SGD)对集体行动有效性的影响。结果表明,尽管差分隐私保护了个体隐私,但其噪声机制显著降低了集体修改数据的影响力。我们通过理论分析建立了集体行动成功率的下界,该下界依赖于集体规模和隐私参数。实验在多个数据集上模拟深度神经网络训练过程,验证了这一趋势。最后,通过简化经济模型分析隐私成本,揭示了效用与参与成本如何影响私有训练下的集体形成。
原文摘要 · Abstract (English)
The integration of AI into daily life has generated considerable attention and excitement, while also raising concerns about automating algorithmic harms and re-entrenching existing social inequities. While the responsible deployment of trustworthy AI systems is a worthy goal, there are many possible ways to realize it, from policy and regulation to improved algorithm design and evaluation. In fact, since AI trains on social data, there is even a possibility for everyday users, citizens, or workers to directly steer the AI system's behavior through Algorithmic Collective Action, by deliberately modifying the data they share with a platform to drive its learning process in their favor. This paper considers how these grassroots efforts to influence AI interact with methods used by AI firms and governments to improve model trustworthiness. In particular, we focus on the setting where the AI firm deploys a differentially private model, motivated by the growing regulatory focus on privacy and data protection. We investigate how the use of Differentially Private Stochastic Gradient Descent (DP-SGD) affects the collective's ability to influence the learning process. Our findings show that while differential privacy protects individual data, it introduces challenges for effective algorithmic collective action. We establish this trade-off formally by characterizing lower bounds on the success of algorithmic collective action under differential privacy as a function of the collective's size and the firm's privacy parameters. We then verify these trends experimentally by simulating collective action during the training of deep neural network classifiers across several datasets. Finally, we perform a stylized economic analysis of privacy costs to integrate additional incentives, analyzing how utility and participation costs influence the formation of collectives under private training regimes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。