arXiv:2509.21296cs.LGcs.AI2025-09被引 1

神经网络训练数据泄露不可靠,过度训练反而更安全

No Prior, No Leakage: Revisiting Reconstruction Attacks in Trained Neural Networks

  • 无先验知识时,存在无限多解,重建结果不可靠
  • 训练数据精确复现仅是偶然,非必然现象
  • 训练越充分的模型越难被重构,兼顾隐私与泛化

神经网络对训练数据的记忆引发隐私与安全担忧。近期研究表明,在特定条件下,可通过模型参数直接重构训练集部分数据。一些方法利用边际最大化带来的隐式偏差,提示通常有益于泛化的性质可能损害隐私。然而,尽管有显著的实证演示,这些攻击的可靠性仍缺乏理论基础。本文从互补视角出发:不追求更强攻击,而是分析现有重构方法的内在弱点与局限性,并识别其失效条件。我们严格证明,若不引入数据先验知识,则存在无穷多个与真实训练集任意远离的替代解,使重构本质上不可靠。实证上进一步表明,训练样本的精确复现仅是偶然发生。研究结果厘清了训练集泄露可能发生的条件,并为缓解重构攻击提供新见解。令人惊讶的是,训练更充分、隐式偏差更强的网络实际上更不易被重构,从而在该设定下调和了隐私与强泛化需求之间的矛盾。

原文摘要 · Abstract (English)

The memorization of training data by neural networks raises pressing concerns for privacy and security. Recent work has shown that, under certain conditions, portions of the training set can be reconstructed directly from model parameters. Some of these methods exploit implicit bias toward margin maximization, suggesting that properties often regarded as beneficial for generalization may actually compromise privacy. Yet despite striking empirical demonstrations, the reliability of these attacks remains poorly understood and lacks a solid theoretical foundation. In this work, we take a complementary perspective: rather than designing stronger attacks, we analyze the inherent weaknesses and limitations of existing reconstruction methods and identify conditions under which they fail. We rigorously prove that, without incorporating prior knowledge about the data, there exist infinitely many alternative solutions that may lie arbitrarily far from the true training set, rendering reconstruction fundamentally unreliable. Empirically, we further demonstrate that exact duplication of training examples occurs only by chance. Our results refine the theoretical understanding of when training set leakage is possible and offer new insights into mitigating reconstruction attacks. Remarkably, we demonstrate that networks trained more extensively, and therefore satisfying implicit bias conditions more strongly -- are, in fact, less susceptible to reconstruction attacks, reconciling privacy with the need for strong generalization in this setting.

隐私保护模型安全数据泄露泛化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。