arXiv:2602.02296cs.LGcs.AI2026-02被引 1

分离模型泛化与隐私风险,提升隐私保护同时减少性能损失。

Decoupling Generalizability and Membership Privacy Risks in Neural Networks

  • 发现泛化能力与隐私风险分布在神经网络不同区域
  • 提出PPTP训练原则,在保持泛化性的同时增强隐私保护
  • 适用于需要高隐私保障的场景,如医疗数据建模

深度学习模型在获得特定能力时通常需牺牲部分性能,隐私保护即存在此类权衡。不同防御方法间的损失差异表明,可解耦泛化能力与隐私风险以最大化隐私收益。本文发现,模型的泛化能力与隐私风险存在于深层神经网络的不同层级中。基于此观察,我们提出隐私保护训练原则(PPTP),旨在保护模型组件免受隐私泄露风险,同时最小化泛化性能的下降。通过大量实验验证,该方法在显著提升隐私保护能力的同时,有效维持了模型的泛化性能。

原文摘要 · Abstract (English)

A deep learning model usually has to sacrifice some utilities when it acquires some other abilities or characteristics. Privacy preservation has such trade-off relationships with utilities. The loss disparity between various defense approaches implies the potential to decouple generalizability and privacy risks to maximize privacy gain. In this paper, we identify that the model's generalization and privacy risks exist in different regions in deep neural network architectures. Based on the observations that we investigate, we propose Privacy-Preserving Training Principle (PPTP) to protect model components from privacy risks while minimizing the loss in generalizability. Through extensive evaluations, our approach shows significantly better maintenance in model generalizability while enhancing privacy preservation.

隐私保护泛化能力神经网络

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。