arXiv:2505.20095cs.LG2025-05被引 1

发现神经网络中虚假关联导致隐私泄露差异,且抗偏方法无效。

Spurious Privacy Leakage in Neural Networks

  • 揭示虚假关联使某些群体更易遭隐私攻击
  • 简单任务下隐私差距更大,因模型依赖虚假特征
  • 抗偏方法不降低隐私风险,因仍会记忆敏感信息

在真实世界数据上训练的神经网络常表现出偏差,同时易受隐私攻击。尽管对两类问题的研究较多,其交叉影响仍不明确。本文研究虚假相关性带来的隐私影响,提出‘虚假隐私泄露’现象:虚假分组比非虚假分组更易受隐私攻击。我们发现,在目标较简单的任务(如类别较少)中,因依赖虚假特征,群体间隐私差异更大。反直觉的是,旨在减少虚假偏差的鲁棒方法未能缓解隐私差距,原因在于这些方法虽降低预测对虚假特征的依赖,却无法阻止训练期间对它们的记忆。最后,我们系统比较了不同架构在含虚假数据下的隐私表现,发现与以往研究相反,模型架构选择会影响隐私评估结果。

原文摘要 · Abstract (English)

Neural networks trained on real-world data often exhibit biases while simultaneously being vulnerable to privacy attacks aimed at extracting sensitive information. Despite extensive research on each problem individually, their intersection remains poorly understood. In this work, we investigate the privacy impact of spurious correlation bias. We introduce \emph{spurious privacy leakage}, a phenomenon in which spurious groups are significantly more vulnerable to privacy attacks than non-spurious groups. We observe that privacy disparity between groups increases in tasks with simpler objectives (e.g. fewer classes) due to spurious features. Counterintuitively, we demonstrate that spurious robust methods, designed to reduce spurious bias, fail to mitigate privacy disparity. Our analysis reveals that this occurs because robust methods can reduce reliance on spurious features for prediction, but do not prevent their memorization during training. Finally, we systematically compare the privacy of different model architectures trained with spurious data, demonstrating that, contrary to previous work, architectural choice can affect privacy evaluation.

隐私泄露虚假相关神经网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。