提出新方法评估并减少不同群体在隐私保护中的风险差异。
On the Fairness of Privacy Protection: Measuring and Mitigating the Disparity of Group Privacy Risks for Differentially Private Machine Learning
- 设计新型成员推理游戏,高效评估数据记录的近似最坏情况隐私风险。
- 实验显示该方法更严格地测量群体隐私风险差异,提升评估可靠性。
- 改进DP-SGD算法,通过自适应分组梯度裁剪,增强隐私公平性。
尽管在公平感知机器学习和差分隐私机器学习方面取得了显著进展,但不同群体间隐私保护的公平性仍研究不足。现有方法基于数据记录的平均隐私风险评估群体隐私风险,可能低估实际风险,从而低估群体间差异。同时,当前最坏情况隐私风险评估方法计算耗时,难以实用。为此,本文提出一种新型成员推理游戏,可高效审计数据记录的近似最坏情况隐私风险。实验表明,该方法提供了更严格的群体隐私风险测量,可靠评估了风险差异。此外,为促进差分隐私机器学习中的隐私公平性,我们基于差分隐私审计中“信标”设计思想,改进标准DP-SGD算法,引入自适应分组梯度裁剪策略。大量实验验证,该算法有效降低群体隐私风险差异,提升隐私保护公平性。
原文摘要 · Abstract (English)
While significant progress has been made in conventional fairness-aware machine learning (ML) and differentially private ML (DPML), the fairness of privacy protection across groups remains underexplored. Existing studies have proposed methods to assess group privacy risks, but these are based on the average-case privacy risks of data records. Such approaches may underestimate the group privacy risks, thereby potentially underestimating the disparity across group privacy risks. Moreover, the current method for assessing the worst-case privacy risks of data records is time-consuming, limiting their practical applicability. To address these limitations, we introduce a novel membership inference game that can efficiently audit the approximate worst-case privacy risks of data records. Experimental results demonstrate that our method provides a more stringent measurement of group privacy risks, yielding a reliable assessment of the disparity in group privacy risks. Furthermore, to promote privacy protection fairness in DPML, we enhance the standard DP-SGD algorithm with an adaptive group-specific gradient clipping strategy, inspired by the design of canaries in differential privacy auditing studies. Extensive experiments confirm that our algorithm effectively reduces the disparity in group privacy risks, thereby enhancing the fairness of privacy protection in DPML.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。