为敏感特征推断的最小均方误差设定理论下界,兼顾严谨性与实用性。
Lower Bounds on the MMSE of Adversarially Inferring Sensitive Features
- 基于有限样本和线性模型,用经验均方误差加误差项建立下界
- 推导出噪声方差最优的闭式边界,适用于多种特征关系
- 适合关注隐私推理风险评估的研究者或系统设计者
我们提出一种基于最小均方误差(MMSE)估计的对抗性评估框架,用于从其他相关特征的噪声观测中推断敏感特征。该方法在有限样本和线性预测模型条件下,建立了真实MMSE的理论下界,其形式由受限假设类下的经验MMSE与一个非负误差项构成。该误差项同时包含因样本数量有限导致的估计误差和因假设类受限引起的近似误差。对于线性预测模型,我们在敏感特征与非敏感特征间存在线性映射、二元对称信道及类别条件多维高斯分布等多种关系时,推导出关于近似误差的闭式下界,且在噪声方差上为阶最优。此外,我们还提出一种新下界,基于在保留验证集上计算的MMSE估计器均方误差,该估计器是在有限样本和受限假设类上训练得到的。实验表明,本框架能有效平衡理论保证与实际效率,实现基于MMSE的对抗性敏感特征推断评估。
原文摘要 · Abstract (English)
We propose an adversarial evaluation framework for sensitive feature inference based on minimum mean-squared error (MMSE) estimation with a finite sample size and linear predictive models. Our approach establishes theoretical lower bounds on the true MMSE of inferring sensitive features from noisy observations of other correlated features. These bounds are expressed in terms of the empirical MMSE under a restricted hypothesis class and a non-negative error term. The error term captures both the estimation error due to finite number of samples and the approximation error from using a restricted hypothesis class. For linear predictive models, we derive closed-form bounds, which are order optimal in terms of the noise variance, on the approximation error for several classes of relationships between the sensitive and non-sensitive features, including linear mappings, binary symmetric channels, and class-conditional multi-variate Gaussian distributions. We also present a new lower bound that relies on the MSE computed on a hold-out validation dataset of the MMSE estimator learned on finite-samples and a restricted hypothesis class. Through empirical evaluation, we demonstrate that our framework serves as an effective tool for MMSE-based adversarial evaluation of sensitive feature inference that balances theoretical guarantees with practical efficiency.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。