arXiv:2506.03467cs.ITcs.CR2025-06被引 2

用KL散度优化高斯混合模型的隐私发布,兼顾安全与精度。

Differentially Private Distribution Release of Gaussian Mixture Models via KL-Divergence Minimization

  • 以KL散度为指标,优化隐私保护下的模型准确性
  • 通过可控噪声扰动实现(ε,δ)-差分隐私,保障参数安全
  • 适用于需保护数据隐私的统计建模与机器学习场景

高斯混合模型(GMM)广泛应用于多模态数据分布的建模,在数据挖掘、模式识别、数据模拟和机器学习中具有重要价值。然而,近期研究表明,直接发布GMM参数会带来显著隐私风险,可能泄露底层数据的敏感信息。本文针对在确保差分隐私(DP)的前提下释放GMM参数的问题展开研究,重点关注混合权重、分量均值和协方差矩阵的隐私保护。提出以Kullback-Leibler(KL)散度作为评估发布后模型准确性的效用度量,因其能综合反映噪声扰动对所有参数的影响。为实现隐私保护,设计了一种添加精心校准随机扰动的DP机制。通过理论分析,量化了隐私预算分配与扰动统计特性对DP保证的影响,并推导出可计算的KL散度表达式。进一步构建并求解一个在给定(ε, δ)-DP约束下最小化原模型与发布模型间KL散度的优化问题。在合成与真实世界数据集上的大量实验表明,该方法在保持高模型效用的同时,实现了强隐私保障。

原文摘要 · Abstract (English)

Gaussian Mixture Models (GMMs) are widely used statistical models for representing multi-modal data distributions, with numerous applications in data mining, pattern recognition, data simulation, and machine learning. However, recent research has shown that releasing GMM parameters poses significant privacy risks, potentially exposing sensitive information about the underlying data. In this paper, we address the challenge of releasing GMM parameters while ensuring differential privacy (DP) guarantees. Specifically, we focus on the privacy protection of mixture weights, component means, and covariance matrices. We propose to use Kullback-Leibler (KL) divergence as a utility metric to assess the accuracy of the released GMM, as it captures the joint impact of noise perturbation on all the model parameters. To achieve privacy, we introduce a DP mechanism that adds carefully calibrated random perturbations to the GMM parameters. Through theoretical analysis, we quantify the effects of privacy budget allocation and perturbation statistics on the DP guarantee, and derive a tractable expression for evaluating KL divergence. We formulate and solve an optimization problem to minimize the KL divergence between the released and original models, subject to a given $(ε, δ)$-DP constraint. Extensive experiments on both synthetic and real-world datasets demonstrate that our approach achieves strong privacy guarantees while maintaining high utility.

差分隐私高斯混合模型KL散度隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。