arXiv:2604.18352cs.CRcs.AI2026-04中稿 · the Theory and Pra…

提出新方法精准审计差分隐私生成模型的隐私保护效果。

Tight Auditing of Differential Privacy in MST and AIM

  • 基于高斯差分隐私构建完整真假阳性权衡的审计框架。
  • 在强隐私场景下对MST和AIM首次实现紧密审计,实测μ≈0.43。
  • 适合关注隐私保障可信度的研究者与应用开发者。

当前先进的差分隐私合成数据生成器如MST和AIM被广泛应用,但对其隐私保证进行精确审计仍具挑战。本文提出一种基于高斯差分隐私(GDP)的审计框架,通过全面衡量假阳性与假阴性的权衡来评估隐私水平。在最坏情况设置下应用于MST和AIM,该方法首次在强隐私范围内实现了紧密审计。当(ε,δ)=(1,10⁻²)时,实测μ_{emp}≈0.43,与理论预期μ=0.45接近,表明理论与实践差距很小。代码已公开:https://github.com/sassoftware/dpmm。

原文摘要 · Abstract (English)

State-of-the-art Differentially Private (DP) synthetic data generators such as MST and AIM are widely used, yet tightly auditing their privacy guarantees remains challenging. We introduce a Gaussian Differential Privacy (GDP)-based auditing framework that measures privacy via the full false-positive/false-negative tradeoff. Applied to MST and AIM under worst-case settings, our method provides the first tight audits in the strong-privacy regime. For $(ε,δ)=(1,10^{-2})$, we obtain $μ_{emp}\approx0.43$ vs. implied $μ=0.45$, showing a small theory-practice gap. Our code is publicly available: https://github.com/sassoftware/dpmm.

差分隐私合成数据审计

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。