动态调整隐私预算,提升对抗环境下的数据系统可靠性。
TADP-RME: A Trust-Adaptive Differential Privacy Framework for Enhancing Reliability of Data-Driven Systems
- 根据用户信任度自适应调节隐私预算,实现灵活的隐私与效用平衡。
- 通过反向流形嵌入破坏局部几何结构,使推理攻击成功率降低3.1%。
- 适合需要高可靠性的隐私保护场景,如医疗或金融数据共享。
在对抗环境下确保数据驱动系统的可靠性,需将隐私视为基础组件。尽管差分隐私和密码协议提供强保障,现有方案依赖固定隐私预算,导致效用-隐私权衡僵化,难以应对用户信任异构性。此外,仅添加噪声的差分隐私会保留几何结构,使推理攻击得以利用,造成隐私泄露。我们提出TADP-RME(信任自适应差分隐私与反向流形嵌入),一种在不同信任水平下增强可靠性的框架。该框架引入[0,1]范围内的逆向信任评分,自适应调节隐私预算,实现效用与隐私间的平滑过渡。同时,反向流形嵌入通过非线性变换破坏局部几何关系,通过后处理保持形式上的差分隐私保证。理论与实证结果表明,该方法在不显著降低效用的前提下,将攻击成功率降低最多达3.1%。框架在各类推理攻击中均优于现有方法,为对抗环境下的可靠学习提供了统一解决方案。
原文摘要 · Abstract (English)
Ensuring reliability in adversarial settings necessitates treating privacy as a foundational component of data-driven systems. While differential privacy and cryptographic protocols offer strong guarantees, existing schemes rely on a fixed privacy budget, leading to a rigid utility-privacy trade-off that fails under heterogeneous user trust. Moreover, noise-only differential privacy preserves geometric structure, which inference attacks exploit, causing privacy leakage. We propose TADP-RME (Trust-Adaptive Differential Privacy with Reverse Manifold Embedding), a framework that enhances reliability under varying levels of user trust. It introduces an inverse trust score in the range [0,1] to adaptively modulate the privacy budget, enabling smooth transitions between utility and privacy. Additionally, Reverse Manifold Embedding applies a nonlinear transformation to disrupt local geometric relationships while preserving formal differential privacy guarantees through post-processing. Theoretical and empirical results demonstrate improved privacy-utility trade-offs, reducing attack success rates by up to 3.1 percent without significant utility degradation. The framework consistently outperforms existing methods against inference attacks, providing a unified approach for reliable learning in adversarial environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。