arXiv:2604.00942cs.LGcs.CR2026-04被引 1

在保护隐私的前提下,用参考数据修复噪声查询点的几何结构。

Differentially Private Manifold Denoising

  • 通过私有估计局部均值与切空间,迭代修正查询点位置。
  • 在中等隐私预算下实现信号精准恢复,收敛速率受样本量与噪声影响。
  • 适合医疗、金融等需严格隐私保护的几何数据分析场景。

我们提出一种差分隐私流形去噪框架,使用户能够利用敏感参考数据修正噪声查询点,同时不泄露隐私。该方法采用迭代流程:(i)在可控敏感度下,私有估计参考数据的局部均值和切空间几何;(ii)在每轮迭代中,将查询点沿私有估计子空间投影至局部均值;(iii)使用$(\varepsilon,δ)$-差分隐私对多轮迭代与查询进行严格的隐私核算。该框架将差分隐私引入流形方法,在保留足够几何信号以支持嵌入、聚类和可视化等下游任务的同时,为参考数据提供形式化隐私保障。实际应用中,流程模块化且可扩展,将差分隐私保护的局部几何(均值与切向量)与受预算约束的查询点更新分离,并通过简单调度器分配隐私预算。在流形正则性、采样密度与测量噪声的标准假设下,我们建立了高概率效用保证,表明修正后的查询点以非渐近速率收敛至流形,该速率由样本量、噪声水平、带宽和隐私预算决定。模拟与案例研究显示,在中等隐私预算下可实现准确信号恢复,清晰揭示了效用与隐私的权衡,为受监管环境中的流形分析工作流提供了可直接部署的差分隐私组件,无需重构隐私系统。

原文摘要 · Abstract (English)

We introduce a differentially private manifold denoising framework that allows users to exploit sensitive reference datasets to correct noisy, non-private query points without compromising privacy. The method follows an iterative procedure that (i) privately estimates local means and tangent geometry using the reference data under calibrated sensitivity, (ii) projects query points along the privately estimated subspace toward the local mean via corrective steps at each iteration, and (iii) performs rigorous privacy accounting across iterations and queries using $(\varepsilon,δ)$-differential privacy (DP). Conceptually, this framework brings differential privacy to manifold methods, retaining sufficient geometric signal for downstream tasks such as embedding, clustering, and visualization, while providing formal DP guarantees for the reference data. Practically, the procedure is modular and scalable, separating DP-protected local geometry (means and tangents) from budgeted query-point updates, with a simple scheduler allocating privacy budget across iterations and queries. Under standard assumptions on manifold regularity, sampling density, and measurement noise, we establish high-probability utility guarantees showing that corrected queries converge toward the manifold at a non-asymptotic rate governed by sample size, noise level, bandwidth, and the privacy budget. Simulations and case studies demonstrate accurate signal recovery under moderate privacy budgets, illustrating clear utility-privacy trade-offs and providing a deployable DP component for manifold-based workflows in regulated environments without reengineering privacy systems.

差分隐私流形学习去噪隐私保护

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。