提出统一的隐私保护机制,平衡分类准确率与隐私安全。
BlockRR: A Unified Framework of RR-type Algorithms for Label Differential Privacy
- 构建统一框架,整合多种随机响应算法。
- 在ε≤3.0时,测试准确率与各类别平均准确率更优。
- 适合关注标签差分隐私的机器学习研究者。
本文提出 BlockRR,一种统一的标签差分隐私随机响应机制。该框架将已有 RR 型机制作为特定参数下的特例,避免了逐案分析的繁琐。理论上,我们证明 BlockRR 满足 ε-标签差分隐私(ε-label DP)。我们设计了一种基于标签先验信息权重矩阵的划分方法,利用并行组合原理保证两个此类机制组合后仍满足 ε-标签 DP。实验在两类存在不同类别不平衡程度的 CIFAR-10 变体上进行。结果表明,在高隐私(ε ≤ 3.0)和中等隐私(ε ≤ 3.0)场景下,所提方法在测试准确率与各类别平均准确率之间取得更好平衡;在低隐私(ε ≥ 4.0)场景下,所有方法退化为标准 RR,无额外性能损失。
原文摘要 · Abstract (English)
In this paper, we introduce BlockRR, a novel and unified randomized-response mechanism for label differential privacy. This framework generalizes existed RR-type mechanisms as special cases under specific parameter settings, which eliminates the need for separate, case-by-case analysis. Theoretically, we prove that BlockRR satisfies $ε$-label DP. We also design a partition method for BlockRR based on a weight matrix derived from label prior information; the parallel composition principle ensures that the composition of two such mechanisms remains $ε$-label DP. Empirically, we evaluate BlockRR on two variants of CIFAR-10 with varying degrees of class imbalance. Results show that in the high-privacy and moderate-privacy regimes ($ε\leq 3.0$), our propsed method gets a better balance between test accuaracy and the average of per-class accuracy. In the low-privacy regime ($ε\geq 4.0$), all methods reduce BlockRR to standard RR without additional performance loss.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。