arXiv:2509.18949cs.LGcs.AI2025-09中稿 · ECAI2025 conferenc…被引 1

用可信网络平衡贝叶斯模型的隐私与可用性

Towards Privacy-Aware Bayesian Networks: A Credal Approach

  • 用可信网络替代传统贝叶斯网络,通过参数模糊化实现隐私保护
  • 实验显示调整超参数可灵活调节隐私强度,且不影响有效推理
  • 适合关注数据隐私的医疗、金融等领域的模型发布者

贝叶斯网络(BN)是高效的概率图模型,在医疗、生物信息学和经济等领域广泛应用。其结构与参数通常由专家设定或从数据中学习获得。然而,随着隐私问题日益严重,公开发布的模型常因缺乏隐私设计而面临追踪攻击风险:攻击者结合公开模型与辅助数据,可推断特定个体是否参与训练。现有防护方法通过向参数添加噪声来增强隐私,但严重损害模型推理的准确性与意义。本文提出可信网络(CN)作为新解决方案,通过适配追踪攻击定义,证明CN能隐藏学习到的BN结构,降低攻击成功率。相比加噪版本,CN是模糊化而非噪声化的模型,可在保障隐私的同时保持有效推理。我们识别出需隐藏的关键学习信息以防止模型恢复。通过数值实验发现,调节CN超参数可动态控制隐私水平。结果表明,CN为构建隐私友好的概率图模型提供了系统、实用且高效的方法。

原文摘要 · Abstract (English)

Bayesian networks (BN) are probabilistic graphical models that enable efficient knowledge representation and inference. These have proven effective across diverse domains, including healthcare, bioinformatics and economics. The structure and parameters of a BN can be obtained by domain experts or directly learned from available data. However, as privacy concerns escalate, it becomes increasingly critical for publicly released models to safeguard sensitive information in training data. Typically, released models do not prioritize privacy by design. In particular, tracing attacks from adversaries can combine the released BN with auxiliary data to determine whether specific individuals belong to the data from which the BN was learned. State-of-the-art protection tecniques involve introducing noise into the learned parameters. While this offers robust protection against tracing attacks, it significantly impacts the model's utility, in terms of both the significance and accuracy of the resulting inferences. Hence, high privacy may be attained at the cost of releasing a possibly ineffective model. This paper introduces credal networks (CN) as a novel solution for balancing the model's privacy and utility. After adapting the notion of tracing attacks, we demonstrate that a CN enables the masking of the learned BN, thereby reducing the probability of successful attacks. As CNs are obfuscated but not noisy versions of BNs, they can achieve meaningful inferences while safeguarding privacy. Moreover, we identify key learning information that must be concealed to prevent attackers from recovering the underlying BN. Finally, we conduct a set of numerical experiments to analyze how privacy gains can be modulated by tuning the CN hyperparameters. Our results confirm that CNs provide a principled, practical, and effective approach towards the development of privacy-aware probabilistic graphical models.

隐私保护概率图模型可信网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。