arXiv:2605.01137cs.LGcs.CR2026-05

提出新隐私度量mPL,解决联合观察下的隐私泄露问题。

Metric-Normalized Posterior Leakage (mPL): Attacker-Aligned Privacy for Joint Consumption

论文配图:Metric-Normalized Posterior Leakage (mPL): Attacker-Aligned Privacy for Joint Consumption
图 1 · 摘自论文原文
  • 定义攻击者对齐的后验泄露度量mPL,基于语义距离校准隐私风险
  • 联合消费下满足mDP仍可能高mPL,因模型聚合相关数据证据
  • 提出AmPL框架动态调参,在低效用损失下显著降低违规频率

度量差分隐私(mDP)通过将噪声按语义距离缩放,强化了局部差分隐私(LDP),但许多机器学习系统在联合观察下运行,此时依赖单记录的隐私保证可能遗漏由证据聚合引发的泄露。本文提出度量归一化后验泄露(mPL),一种攻击者对齐、距离校准的后验优势变化度量,并证明在单一或独立发布场景中,均匀约束mPL等价于mDP。然而在联合观察下,满足mDP仍可能导致高mPL,因为学习到的聚合器会累积相关项的证据。为提升可操作性,我们形式化了概率有界mPL(PBmPL),限制mPL超过目标预算的频率,并通过自适应mPL(AmPL)实现:扰动、以学习攻击者审计、调整参数(可选贝叶斯重映射),以平衡隐私与效用。在词嵌入案例研究中,神经攻击者在联合消费下仍违反mPL,而即使采用每记录的mDP扰动;而AmPL大幅降低此类违规频率,且效用损失极小,表明PBmPL是联合消费场景下可验证、实用的隐私保护方案。

原文摘要 · Abstract (English)

Metric differential privacy (mDP) strengthens local differential privacy (LDP) by scaling noise to semantic distance, but many machine learning (ML) systems are consumed under joint observation, where model-agnostic, per-record guarantees can miss leakage from evidence aggregation. We introduce metric-normalized posterior leakage (mPL), an attacker-aligned, distance-calibrated measure of posterior-odds shift induced by releases, and show that for single or independent releases, uniformly bounding mPL is equivalent to mDP. Under joint observation, however, satisfying mDP may still leave mPL high because learned aggregators compound evidence across correlated items. To make control practical, we formalize probabilistically bounded mPL (PBmPL), which limits how often mPL may exceed a target budget, and we operationalize it via Adaptive mPL (AmPL), a trust-and-verify framework that perturbs, audits with a learned attacker, and adapts parameters (with optional Bayesian remapping) to balance privacy and utility. In a word-embedding case study, neural adversaries violate mPL under joint consumption despite per-record mDP perturbations, whereas AmPL substantially lowers the frequency of such violations with low utility loss, indicating PBmPL as a practical, certifiable protection for joint-consumption settings.

隐私保护差分隐私联合消费攻击者建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。