对比私有生成模型的隐私漏洞,发现GAN比扩散模型更抗成员推理攻击。
On the MIA Vulnerability Gap Between Private GANs and Diffusion Models
- 从稳定性理论出发,揭示GAN对数据扰动更不敏感。
- 实验证明在多种数据集和隐私预算下,GAN隐私泄露显著低于扩散模型。
- 适合关注生成模型隐私安全的研究者与应用开发者。
生成对抗网络(GANs)和扩散模型已成为高质量图像合成的主流方法。尽管两者均可在差分隐私(DP)下训练以保护敏感数据,但它们对成员推理攻击(MIA)的敏感性——这一威胁数据机密性的关键问题——仍不清楚。本文首次对不同私有生成模型的隐私风险进行统一的理论与实证分析。通过基于稳定性的分析,我们发现GAN对数据扰动的敏感性显著低于扩散模型,暗示其在抵御MIA方面具有结构优势。随后,我们使用标准化的MIA流程,在多个数据集和隐私预算下进行全面实证研究。结果一致表明,即使在强差分隐私条件下,GAN仍展现出明显的隐私鲁棒性优势,凸显模型类型本身可显著影响隐私泄露程度。
原文摘要 · Abstract (English)
Generative Adversarial Networks (GANs) and diffusion models have emerged as leading approaches for high-quality image synthesis. While both can be trained under differential privacy (DP) to protect sensitive data, their sensitivity to membership inference attacks (MIAs), a key threat to data confidentiality, remains poorly understood. In this work, we present the first unified theoretical and empirical analysis of the privacy risks faced by differentially private generative models. We begin by showing, through a stability-based analysis, that GANs exhibit fundamentally lower sensitivity to data perturbations than diffusion models, suggesting a structural advantage in resisting MIAs. We then validate this insight with a comprehensive empirical study using a standardized MIA pipeline to evaluate privacy leakage across datasets and privacy budgets. Our results consistently reveal a marked privacy robustness gap in favor of GANs, even in strong DP regimes, highlighting that model type alone can critically shape privacy leakage.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。