提出首个最优的瑞尼差分隐私审计方法,精准评估模型隐私泄露风险。
Optimal Guarantees for Auditing Rényi Differentially Private Machine Learning
- 基于假设检验与变分估计,直接计算邻近执行间的瑞尼散度。
- 在小到中等瑞尼阶数下,审计精度显著优于现有黑盒方法。
- 理论证明样本复杂度近乎最优,适合高要求隐私验证场景。
我们研究声称具备瑞尼差分隐私(RDP)保证的机器学习算法的黑盒审计问题。提出一种基于假设检验的审计框架,利用多斯克尔-瓦拉达汉(DV)变分估计器,直接估算邻近执行间的瑞尼散度。分析给出了通过类别受限的DV估计器进行RDP审计的显式非渐近置信区间,将统计估计误差与算法隐私泄漏分离。证明了匹配的极小极大下界,表明我们的样本复杂度保证在对数因子范围内信息论最优,从而首次建立了基于DV估计器审计RDP的最优性。实验上,我们在完全黑盒设置下实例化该框架用于审计DP-SGD,在MNIST和CIFAR-10数据集上,覆盖广泛隐私范围,相比之前最先进的黑盒方法,在小至中等瑞尼阶数下均实现显著的实证下界提升,这些阶数下的精确审计最具挑战性。
原文摘要 · Abstract (English)
We study black-box auditing for machine learning algorithms that claim R \ 'enyi differential privacy (RDP) guarantees. We introduce an auditing framework, based on hypothesis testing, that directly estimates Rényi divergence between neighboring executions using the Donsker-Varadhan (DV) variational estimator. Our analysis yields explicit and non-asymptotic confidence intervals for RDP auditing via class-restricted DV estimators, separating statistical estimation error from algorithmic privacy leakage. We prove matching minimax lower bounds showing that, up to logarithmic factors, our sample-complexity guarantees are information-theoretically optimal, thereby establishing the first optimal guarantees for auditing RDP via DV estimators. Empirically, we instantiate our framework for auditing DP-SGD in a fully black-box setting. Across MNIST and CIFAR-10, and over a wide range of privacy regimes, our auditors produce a strong overall improvement on empirical RDP lower bounds compared to prior state-of-the-art black-box methods especially at small and moderate Rényi orders where accurate auditing is most challenging.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。