arXiv:2509.05350cs.CRcs.LG2025-09被引 7

提出集成成员推理攻击,提升合成表格数据隐私审计的鲁棒性。

Ensembling Membership Inference Attacks Against Tabular Generative Models

  • 通过集成多种成员推理攻击方法,增强隐私泄露检测能力。
  • 实验表明单一攻击在不同模型和数据集上表现不一,无统一最优策略。
  • 无监督集成策略显著降低后悔值,适合实际隐私评估场景。

成员推理攻击(MIAs)已成为评估表格生成模型合成数据隐私性的系统化框架,已有多种方法针对不同隐私泄露信号进行设计。然而,在真实威胁场景中,攻击者必须选择单一方法,而无法事先保证其为最优。本文将此问题建模为不确定性下的决策问题,并开展了迄今为止最大规模的合成数据隐私基准测试。结果表明,在不同模型架构和数据领域下,不存在对所有情况都占优的单一攻击方法。基于此发现,本文提出集成成员推理攻击,证明基于个体攻击构建的无监督集成策略在实证上更具鲁棒性,能有效最小化后悔值。

原文摘要 · Abstract (English)

Membership Inference Attacks (MIAs) have emerged as a principled framework for auditing the privacy of synthetic data generated by tabular generative models, where many diverse methods have been proposed that each exploit different privacy leakage signals. However, in realistic threat scenarios, an adversary must choose a single method without a priori guarantee that it will be the empirically highest performing option. We study this challenge as a decision theoretic problem under uncertainty and conduct the largest synthetic data privacy benchmark to date. Here, we find that no MIA constitutes a strictly dominant strategy across a wide variety of model architectures and dataset domains under our threat model. Motivated by these findings, we propose ensemble MIAs and show that unsupervised ensembles built on individual attacks offer empirically more robust, regret-minimizing strategies than individual attacks.

隐私审计成员推理集成学习合成数据

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。