Rashomon集让模型既更抗攻击又更易泄密,一柄双刃剑。
The Double-Edged Nature of the Rashomon Set for Trustworthy Machine Learning
- 用近似最优模型集合提升对抗攻击下的可切换鲁棒性
- 模型多样性越高,隐私泄露风险越大,存在权衡
- 集合对数据分布微小变化稳定,无需重复计算
现实中的机器学习流程通常不产生单一模型,而是生成一个包含多个近似最优模型的Rashomon集。我们发现这种多重性重塑了可信机器学习的关键方面:在单个模型层面,稀疏可解释模型虽能保护隐私但易受对抗攻击;而大Rashomon集内的多样性带来了反应式鲁棒性——即使某个模型被攻破,从业者也可切换到另一个近似最优模型维持准确率,无需重新训练。然而,相同的多样性也加剧了信息泄露,披露更多近似最优模型会逐步暴露训练数据的丰富细节。这导致了一个由多样性决定的鲁棒性-隐私权衡,我们通过理论和实证分析了该权衡。此外,Rashomon集在小规模分布偏移下具有稳定性,一旦计算完成即可持续使用,无需重算。结果表明,Rashomon集在可信机器学习中既是资源也是风险。
原文摘要 · Abstract (English)
Real-world machine learning (ML) pipelines rarely produce a single model; instead, they produce a Rashomon set of many near-optimal ones. We show that this multiplicity reshapes key aspects of trustworthiness. At the individual-model level, sparse interpretable models tend to preserve privacy but are fragile to adversarial attacks. In contrast, the diversity within a large Rashomon set enables reactive robustness: even when an attack compromises one model, a practitioner can switch to a different near-optimal model that remains accurate, without retraining. However, the same diversity increases information leakage, as disclosing more near-optimal models provides an attacker with progressively richer views of the training data. This produces a robustness-privacy trade-off governed by diversity, which we analyze theoretically and empirically. Beyond this trade-off, Rashomon sets are stable under small distribution shifts, so a set computed once remains valid under such shifts without re-computation. Our results highlight the dual role of Rashomon sets as both a resource and a risk for trustworthy ML.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。