提出新方法抵御数据贡献者伪造身份刷分,提升数据估值公平性。
Quotient Semivalues for False-Name-Resistant Data Attribution

- 基于证据聚类计算贡献值,用代表性节点抵消同一组内重复
- 在合成任务中将伪造攻击收益从1.74降至0.96,接近诚实水平
- 适合关注数据市场公平性的研究者与平台设计者
数据估值方法通常假设贡献者为被动角色,但现实中参与者可通过伪名分裂数据集、复制高价值样本、生成近似副本或伪造合成变体来虚增收益。本文将此行为形式化为机器学习数据估值中的假名操纵问题。提出商值半值机制:在基于证据的归属聚类上而非原始身份计算谢林值、班扎夫值或贝塔值,使用规范代表算子吸收组内重复。证明在固定单调数据价值博弈下,对报告身份实现精确谢林公平性与无限制假名抗性不可兼得,即使在二值实例中亦然,并刻画了通用半值在一致反例上的拆分收益。该机制在两类结构条件下可实现精确假名抗性:组内分配中立性与商值稳定操纵。当溯源不完善时,若条件近似成立,操纵收益与公平损失由三类可度量指标界定:逃逸聚类质量、价值估计误差和聚类距离。在DataMarket-Gym基准测试中,基于示例级证据的商值半值在合成分类任务上将重复与近似重复的假名攻击收益从基线谢林值的1.74降至0.96,接近诚实水平。余弦阈值与(假合并、假拆分)率扫描揭示了公平性与假名攻击之间的权衡边界。
原文摘要 · Abstract (English)
Data valuation methods allocate payments and audit training data's contribution to machine-learning pipelines; however, they often assume passive contributors. In reality, contributors can split datasets across pseudonymous identities, duplicate high-value examples, create near-duplicates, or launder synthetic variants to inflate their share. We formalize this as false-name manipulation in ML data attribution. Our main construction is the quotient semivalue mechanism: compute Shapley-, Banzhaf-, or Beta-style values over evidence-backed attribution clusters instead of raw identities, using a canonical-representative operator to absorb within-cluster duplication. We prove an impossibility: on a fixed monotone data-value game, exact Shapley-fair attribution over reported identities is incompatible with unrestricted false-name-proofness, even on binary-valued instances, and characterize the split-gain of a general semivalue on a unanimity counter-example. The mechanism is exactly false-name-proof under two structural conditions: false-name-neutral within-cluster allocation and quotient-stable manipulations. Under imperfect provenance, when these conditions hold approximately, manipulation gain and fairness loss are bounded by three measurable quantities: escaped-cluster mass, value-estimation error, and clustering distance. We instantiate the mechanisms in DataMarket-Gym, a benchmark for attribution under strategic provider attacks. On synthetic classification tasks, quotient semivalues with example-level evidence reduce manipulation gain on duplicate and near-duplicate Sybil attacks from $1.74$ under baseline Shapley to $0.96$, near the honest level. The cosine-threshold and (false-merge, false-split) rate sweeps trace the corresponding fairness--Sybil frontier.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。