arXiv:2505.23658cs.CRcs.LG2025-05

从贝叶斯视角重新理解数据重建,提出新安全定义防重构攻击。

Bayesian Perspective on Memorization and Reconstruction

  • 用贝叶斯框架分析数据重建问题,构建新安全模型。
  • 证明在特定条件下可有效防范重构攻击,突破原有不可能性结论。
  • 揭示指纹码攻击本质是成员推断攻击,非重构攻击,适合隐私研究者阅读。

我们提出一种新的贝叶斯视角来理解数据重建问题,并基于此构建一个新安全定义,在某些场景下可严格防止重构攻击。该范式帮助我们重新审视隐私与记忆化领域中最著名的攻击之一——指纹码攻击(FPC)。我们认为,这类攻击本质上属于成员推断攻击,而非重构攻击。此外,若仅需防范重构攻击(而不必防范成员推断),则在某些情况下,由指纹码攻击导出的不可能性结果不再成立。

原文摘要 · Abstract (English)

We introduce a new Bayesian perspective on the concept of data reconstruction, and leverage this viewpoint to propose a new security definition that, in certain settings, provably prevents reconstruction attacks. We use our paradigm to shed new light on one of the most notorious attacks in the privacy and memorization literature - fingerprinting code attacks (FPC). We argue that these attacks are really a form of membership inference attacks, rather than reconstruction attacks. Furthermore, we show that if the goal is solely to prevent reconstruction (but not membership inference), then in some cases the impossibility results derived from FPC no longer apply.

隐私保护贝叶斯方法成员推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。