arXiv:2507.12497stat.MEcs.LG2025-07被引 1

提出隐私保护的置信预测新方法,兼顾准确性与数据安全。

Differentially Private Conformal Prediction via Quantile Binary Search

  • 用量化二分搜索法在校准阶段保护隐私
  • 在有限样本下略低于目标覆盖率但整体稳定
  • 适合对隐私和预测精度都有要求的研究者

大多数差分隐私(DP)方法关注模型训练时的数据泄露,却较少考虑校准数据集带来的隐私风险,而后者在不确定性量化方法如共形预测(CP)中很常见。本文提出通用的DP-CP方法P-COQS,通过适配已有随机二分搜索算法计算校准阶段的DP分位数,保障后续预测集的隐私性。尽管在有限样本下会出现轻微覆盖不足(相对于预设的1−α水平),但大量实验证明其在多数情况下仍能接近目标覆盖率。我们验证了该算法的性质,并量化了其近似覆盖性能,对比了现有方法。实验涵盖CIFAR-10、ImageNet和CoronaHack等基准数据集,结果表明P-COQS对隐私噪声具有鲁棒性,在实际覆盖率、效率和信息量上优于当前主流DP方法,且生成更小的预测集同时满足目标覆盖率与隐私约束。

原文摘要 · Abstract (English)

Most Differentially Private (DP) approaches focus on limiting privacy leakage from learners based on the data that they are trained on, there are fewer approaches that consider leakage when procedures involve a calibration dataset which is common in uncertainty quantification methods such as Conformal Prediction (CP). Since there is a limited amount of approaches in this direction, in this work we deliver a general DP approach for CP that we call Private Conformity via Quantile Search (P-COQS). The proposed approach adapts an existing randomized binary search algorithm for computing DP quantiles in the calibration phase of CP thereby guaranteeing privacy of the consequent prediction sets. This however comes at a price of slightly under-covering with respect to the desired $(1 - α)$-level when using finite-sample calibration sets (although broad empirical results show that the P-COQS generally targets the required level in the considered cases). Confirming properties of the adapted algorithm and quantifying the approximate coverage guarantees of the consequent CP, we conduct extensive experiments to examine the effects of privacy noise, sample size and significance level on the performance of our approach compared to existing alternatives. In addition, we empirically evaluate our approach on several benchmark datasets, including CIFAR-10, ImageNet and CoronaHack. Our results suggest that the proposed method is robust to privacy noise and performs favorably with respect to the current DP alternative in terms of empirical coverage, efficiency, and informativeness. Specifically, the results indicate that P-COQS produces smaller conformal prediction sets while simultaneously targeting the desired coverage and privacy guarantees in all these experimental settings.

差分隐私共形预测量化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。