arXiv:2603.00342cs.CRcs.AI2026-03

研究如何在保护隐私前提下实现数据价值评估,避免泄露训练数据信息。

Challenges in Enabling Private Data Valuation

  • 识别出常见估值方法中导致敏感度过高的核心算法机制
  • 发现隐私保护会显著降低数据排序准确性,尤其在稀有样本影响大的场景
  • 提出更适配隐私保护的设计原则,适合关注数据安全的研究者

数据估值方法用于衡量单个训练样本对模型行为的贡献,正被广泛应用于数据集筛选、审计及新兴数据市场。随着其实际应用,隐私风险凸显:估值结果可能暴露某个人的数据是否被使用、是否具有异常影响力,或揭示专有数据集中的敏感模式。这催生了隐私保护型数据估值的研究。然而,差分隐私(DP)与估值效用存在根本矛盾——DP要求输出对任一记录不敏感,而估值本就旨在量化每条记录的影响。因此,简单加噪会破坏区分细微差异的能力,尤其在异构数据集中罕见样本影响巨大的情况下。本文分析了符合差分隐私的数据估值可行性,识别出主流估值框架中的高敏感性核心组件,并解释为何直接应用DP机制会失效。进一步提出了更具隐私友好性的设计原则,并实证评估了隐私约束下各类方法在典型数据集上的排序保真度下降情况。研究厘清了现有方法的局限性,为在严格隐私保障下仍具实用性的估值方法提供了基础。

原文摘要 · Abstract (English)

Data valuation methods quantify how individual training examples contribute to a model's behavior, and are increasingly used for dataset curation, auditing, and emerging data markets. As these techniques become operational, they raise serious privacy concerns: valuation scores can reveal whether a person's data was included in training, whether it was unusually influential, or what sensitive patterns exist in proprietary datasets. This motivates the study of privacy-preserving data valuation. However, privacy is fundamentally in tension with valuation utility under differential privacy (DP). DP requires outputs to be insensitive to any single record, while valuation methods are explicitly designed to measure per-record influence. As a result, naive privatization often destroys the fine-grained distinctions needed to rank or attribute value, particularly in heterogeneous datasets where rare examples exert outsized effects. In this work, we analyze the feasibility of DP-compatible data valuation. We identify the core algorithmic primitives across common valuation frameworks that induce prohibitive sensitivity, explaining why straightforward DP mechanisms fail. We further derive design principles for more privacy-amenable valuation procedures and empirically characterize how privacy constraints degrade ranking fidelity across representative methods and datasets. Our results clarify the limits of current approaches and provide a foundation for developing valuation methods that remain useful under rigorous privacy guarantees.

数据估值差分隐私隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。