提出一种无需模型知识的隐私审计方法,检测合成数据泄露风险。
Privacy Auditing Synthetic Data Release through Local Likelihood Attacks
- 基于局部似然比构建无模型访问的隐私攻击,利用生成模型过拟合特性。
- 在多种数据集和模型上均优于现有方法,低误报率下优势显著。
- 适合关注合成数据隐私风险的研究者与数据发布方使用。
评估合成数据的隐私泄露是重要但未解决的问题。现有框架依赖启发式方法和不现实的模型访问假设,难以有效描述或检测训练数据通过合成数据释放所暴露的风险。本文研究针对表格生成模型倾向于对训练分布某些区域严重过拟合的现象,设计成员推断攻击(MIAs)。提出新型、计算高效的无盒式成员推断攻击——生成似然比攻击(Gen-LRA),无需模型知识或访问权限,通过评估测试样本对替代模型在合成数据上局部似然比估计的影响来实施攻击。我们建立了理论框架:证明Gen-LRA得分可表征为局部密度比统计量,并在一般局部过拟合模型下,证明成员与非成员间存在可检验的均值得分差距。在受控模拟中验证预测,在涵盖多样化数据集、生成模型架构和攻击参数的全面基准上评估。结果表明,跨各项指标,Gen-LRA持续优于现有攻击,在低假阳性率下表现尤为突出。这些结果凸显其作为合成数据发布隐私审计工具的有效性,并揭示了真实应用中生成模型过拟合带来的重大隐私风险。
原文摘要 · Abstract (English)
Auditing the privacy leakage of synthetic data is an important but unresolved problem. Existing privacy auditing frameworks for synthetic data rely on heuristics and unrealistic assumptions about model access, offering limited ability to describe or detect the privacy exposure of training data through synthetic data release. In this paper, we study designing membership inference attacks (MIAs) that specifically exploit the observation that tabular generative models tend to significantly overfit to certain regions of the training distribution. We propose \emph{Generative Likelihood Ratio Attack} (Gen-LRA), a novel, computationally efficient No-Box MIA that, with no assumption of model knowledge or access, formulates its attack by evaluating the influence a test observation has on a surrogate model's estimate of a local likelihood ratio over the synthetic data. We develop a theoretical framework for the attack: we show that the Gen-LRA score admits a closed-form characterization as a localized density-ratio statistic, and we prove that under a general model of local overfitting it produces a provable mean-score gap between members and non-members, yielding testable predictions for when the attack should succeed. We validate these predictions in a controlled simulation study and assess Gen-LRA against a comprehensive benchmark spanning diverse datasets, generative model architectures, and attack parameters. Across metrics, Gen-LRA consistently dominates competing MIAs, with especially strong gains at low false positive rates. These results underscore Gen-LRA's effectiveness as a privacy auditing tool for the release of synthetic data, and highlight the significant privacy risks posed by generative model overfitting in real-world applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。