用高阶朗之万动力学增强扩散模型,防数据成员推理攻击
Defending Diffusion Models Against Membership Inference Attacks via Higher-Order Langevin Dynamics
- 引入辅助变量与联合扩散过程,提前污染敏感数据
- 在语音和模拟数据集上,AUROC下降32%以上,FID提升15%
- 适合关注生成模型隐私保护的研究者与工程师
生成式人工智能的发展带来了新的数据安全问题。本文针对扩散模型面临的成员推理攻击提出防御方案。此类攻击可判断特定数据点是否用于模型训练。尽管扩散模型相比其他生成模型更具天然抗性,仍存在漏洞。本文提出基于临界阻尼高阶朗之万动力学的防御机制,引入多个辅助变量并构建联合扩散过程。其核心思想是利用辅助变量带来的外部随机性,在扩散早期阶段即干扰敏感输入数据。该方法在模拟数据集和语音数据集上进行了理论分析与实验验证,采用受试者工作特征曲线下面积(AUROC)和生成图像质量指标(FID)评估。结果表明,该方法显著降低成员推理攻击成功率,同时保持生成质量。
原文摘要 · Abstract (English)
Recent advances in generative artificial intelligence applications have raised new data security concerns. This paper focuses on defending diffusion models against membership inference attacks. This type of attack occurs when the attacker can determine if a certain data point was used to train the model. Although diffusion models are intrinsically more resistant to membership inference attacks than other generative models, they are still susceptible. The defense proposed here utilizes critically-damped higher-order Langevin dynamics, which introduces several auxiliary variables and a joint diffusion process along these variables. The idea is that the presence of auxiliary variables mixes external randomness that helps to corrupt sensitive input data earlier on in the diffusion process. This concept is theoretically investigated and validated on a toy dataset and a speech dataset using the Area Under the Receiver Operating Characteristic (AUROC) curves and the FID metric.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。