arXiv:2507.09678cs.LGcs.AI2025-07

在加密数据上用置信预测,实现隐私保护下的可靠不确定性量化。

Conformal Prediction for Privacy-Preserving Machine Learning

  • 直接在加密数据上应用置信预测,利用固定密钥保持数据可交换性。
  • 加密模型测试准确率达36.88%,远高于随机猜测的9.56%;e值方法覆盖率达60%以上。
  • 适合关注隐私安全与预测可靠性平衡的研究者和系统设计者。

我们研究了置信预测(CP)与确定性加密数据上的监督学习相结合的可行性,旨在弥合严格不确定性量化与隐私保护机器学习之间的差距。使用AES加密的MNIST数据集变体,我们证明即使在加密域直接应用CP方法仍具有效性,这得益于固定密钥加密下数据可交换性的保持。我们对比了基于p值与基于e值的置信预测器。实证结果显示,训练于确定性加密数据的模型仍能提取有意义结构,测试准确率达到36.88%,显著高于基于实例加密的随机猜测水平(9.56%)。此外,基于e值的CP在4.3损失阈值校准下实现超过60%的预测集覆盖率,正确捕获5000个测试样本中的4888个真实标签。相比之下,基于p值的CP虽生成更小预测集,但覆盖精度下降。这些发现揭示了在加密数据环境下CP的潜力与局限,强调了预测集紧凑性与可靠性之间的关键权衡。

原文摘要 · Abstract (English)

We investigate the integration of Conformal Prediction (CP) with supervised learning on deterministically encrypted data, aiming to bridge the gap between rigorous uncertainty quantification and privacy-preserving machine learning. Using AES-encrypted variants of the MNIST dataset, we demonstrate that CP methods remain effective even when applied directly in the encrypted domain, owing to the preservation of data exchangeability under fixed-key encryption. We test traditional $p$-value-based against $e$-value-based conformal predictors. Our empirical evaluation reveals that models trained on deterministically encrypted data retain the ability to extract meaningful structure, achieving 36.88\% test accuracy -- significantly above random guessing (9.56\%) observed with per-instance encryption. Moreover, $e$-value-based CP achieves predictive set coverage of over 60\% with 4.3 loss-threshold calibration, correctly capturing the true label in 4888 out of 5000 test cases. In contrast, the $p$-value-based CP yields smaller predictive sets but with reduced coverage accuracy. These findings highlight both the promise and limitations of CP in encrypted data settings and underscore critical trade-offs between prediction set compactness and reliability. %Our work sets a foundation for principled uncertainty quantification in secure, privacy-aware learning systems.

置信预测隐私计算加密机器学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。