揭示深度学习训练中样本隐私泄露的动态演化规律
Evaluating the Dynamics of Membership Privacy in Deep Learning
- 在训练过程中逐样本追踪隐私漏洞,用FPR-TPR平面量化风险变化
- 发现样本隐私风险早期就已确定,与学习难度强相关
- 为构建主动防御隐私泄露的训练策略提供理论依据
成员推理攻击(MIAs)对深度学习训练数据隐私构成严重威胁。尽管攻击方法取得显著进展,但对模型在训练过程中何时以及如何编码成员信息的理解仍有限。本文提出一种动态分析框架,可在个体样本层面解构并量化隐私泄露的动态过程。通过在整个训练过程中追踪每个样本在假阳性率-真阳性率(FPR-TPR)平面上的脆弱性,该框架系统测量了数据集复杂度、模型架构和优化器选择等因素如何影响样本变得易受攻击的速度与程度。关键发现是:样本的内在学习难度与其隐私风险存在稳健相关性;最终模型中高度易受攻击的样本,其隐私风险在训练初期即已基本决定。研究结果深化了对隐私风险动态演变机制的理解,为实现前瞻性、隐私感知的模型训练策略奠定了基础。
原文摘要 · Abstract (English)
Membership inference attacks (MIAs) pose a critical threat to the privacy of training data in deep learning. Despite significant progress in attack methodologies, our understanding of when and how models encode membership information during training remains limited. This paper presents a dynamic analytical framework for dissecting and quantifying privacy leakage dynamics at the individual sample level. By tracking per-sample vulnerabilities on an FPR-TPR plane throughout training, our framework systematically measures how factors such as dataset complexity, model architecture, and optimizer choice influence the rate and severity at which samples become vulnerable. Crucially, we discover a robust correlation between a sample's intrinsic learning difficulty, and find that the privacy risk of samples highly vulnerable in the final trained model is largely determined early during training. Our results thus provide a deeper understanding of how privacy risks dynamically emerge during training, laying the groundwork for proactive, privacy-aware model training strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。