研究扩散模型生成的表格数据隐私风险,发现部分模型易受成员推理攻击。
Membership Inference over Diffusion-models-based Synthetic Tabular Data
- 基于逐步误差对比设计查询式成员推理攻击
- TabDDPM易被攻破,而TabSyn具备较强抗性
- 为合成数据隐私保护提供重要警示与方向
本研究探讨基于扩散模型生成的合成表格数据所面临的隐私风险,重点关注其对成员推理攻击(Membership Inference Attacks, MIAs)的脆弱性。针对两种近期模型——TabDDPM和TabSyn,我们基于逐步误差对比方法构建了查询式成员推理攻击。结果表明,TabDDPM对攻击高度敏感,而TabSyn表现出较强的鲁棒性。研究强调了评估扩散模型隐私影响的重要性,并呼吁进一步探索更可靠的合成数据隐私保护机制。
原文摘要 · Abstract (English)
This study investigates the privacy risks associated with diffusion-based synthetic tabular data generation methods, focusing on their susceptibility to Membership Inference Attacks (MIAs). We examine two recent models, TabDDPM and TabSyn, by developing query-based MIAs based on the step-wise error comparison method. Our findings reveal that TabDDPM is more vulnerable to these attacks. TabSyn exhibits resilience against our attack models. Our work underscores the importance of evaluating the privacy implications of diffusion models and encourages further research into robust privacy-preserving mechanisms for synthetic data generation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。