arXiv:2506.16636stat.MLcs.AI2025-06

通过潜空间加噪生成隐私保护的合成数据,提升高维场景下统计一致性。

Latent Noise Injection for Private and Statistically Aligned Synthetic Data Generation

  • 在潜空间加噪后映射回数据域,保持真实与合成数据一一对应
  • 聚合多份合成数据可恢复经典收敛速度 $1/\sqrt{n}$,实现高效推断
  • 满足局部 $(ε, δ)$-差分隐私,适合生物医学等敏感领域共享

合成数据生成已成为可扩展、隐私保护统计分析的关键。尽管基于生成模型(如归一化流)的方法广泛应用,但在高维设置下常出现收敛缓慢问题,逼近真实数据分布的速度往往低于经典的 $1/\sqrt{n}$ 增长率。为此,我们提出基于掩码自回归流(MAF)的潜空间加噪方法。不直接从训练好的模型采样,而是对潜空间中的每个数据点进行扰动并映射回数据域。该构造保持了观测数据与合成数据之间的一一对应关系,使合成输出在传统采样难以胜任的高维场景下仍能准确反映底层分布。该方法满足局部 $(ε, δ)$-差分隐私,并引入单一扰动参数控制隐私-效用权衡。虽然基于单个合成数据集的估计器收敛较慢,但理论上和实证上均表明,在元分析框架中聚合 $K$ 项研究可恢复经典效率,实现一致且可靠的推断。当扰动参数校准得当时,该方法展现出与原始数据强统计对齐性,并对成员推理攻击具有鲁棒性。结果表明,该方法为去中心化与隐私敏感领域(如生物医学研究)的合成数据共享提供了一种有力替代方案。

原文摘要 · Abstract (English)

Synthetic Data Generation has become essential for scalable, privacy-preserving statistical analysis. While standard approaches based on generative models, such as Normalizing Flows, have been widely used, they often suffer from slow convergence in high-dimensional settings, frequently converging more slowly than the canonical $1/\sqrt{n}$ rate when approximating the true data distribution. To overcome these limitations, we propose a Latent Noise Injection method using Masked Autoregressive Flows (MAF). Instead of directly sampling from the trained model, our method perturbs each data point in the latent space and maps it back to the data domain. This construction preserves a one to one correspondence between observed and synthetic data, enabling synthetic outputs that closely reflect the underlying distribution, particularly in challenging high-dimensional regimes where traditional sampling struggles. Our procedure satisfies local $(ε, δ)$-differential privacy and introduces a single perturbation parameter to control the privacy-utility trade-off. Although estimators based on individual synthetic datasets may converge slowly, we show both theoretically and empirically that aggregating across $K$ studies in a meta analysis framework restores classical efficiency and yields consistent, reliable inference. We demonstrate that with a well-calibrated perturbation parameter, Latent Noise Injection achieves strong statistical alignment with the original data and robustness against membership inference attacks. These results position our method as a compelling alternative to conventional flow-based sampling for synthetic data sharing in decentralized and privacy-sensitive domains, such as biomedical research.

合成数据差分隐私生成模型高维数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。