arXiv:2605.27292cs.LGstat.ML2026-05

提出高效可检测的蜜罐构造方法,提升单次训练隐私审计效果

Detectability in Diversity: Improved Canary Crafting for Privacy Auditing in One Run

  • 基于影响函数贪心初始化,结合双层优化增强蜜罐可检测性
  • 在嵌入空间中促进多样性,使蜜罐干扰最小化,泄露评估更准确
  • 计算成本更低,适合实际部署的隐私审计场景

隐私审计旨在通过成员推断攻击(MIAs)实证评估机器学习模型的隐私泄露,并推导差分隐私(DP)参数的下界。近期的单次运行审计方法通过一次训练过程使用多个“蜜罐”点,避免了传统方法的高成本。本文研究如何高效构造这些蜜罐。受最新理论启发,我们发现蜜罐间的干扰会削弱泄露估计效果,因此提出同时优化蜜罐的可检测性和低干扰性。方法结合基于影响函数的贪心初始化与双层优化,最大化蜜罐间可区分性,同时促进嵌入空间中的多样性,从而支持高效双层算法。实验表明,该方法在更低计算成本下实现了比现有方法更强的隐私泄露估计。

原文摘要 · Abstract (English)

Privacy auditing aims to empirically assess privacy leakage in machine learning models using membership inference attacks (MIAs), and to derive lower bounds on differential privacy (DP) parameters. Recent one-run auditing methods address the high cost of standard approaches by relying on a single training run with multiple "canary" points whose inclusion or exclusion must be detected by the auditor. In this work, we study the problem of efficiently crafting canaries for one-run privacy auditing. Motivated by recent theoretical insights suggesting that interference between canaries contributes to weaker leakage estimates compared to multi-run methods, we propose to optimize canaries to be both highly detectable and minimally interfering. Our approach combines a greedy initialization based on influence functions with a bilevel optimization procedure that maximizes distinguishability while promoting diversity in embedding space, enabling the use of computationally efficient bilevel algorithms. Experiments show that our method achieves stronger privacy leakage estimates at a lower computational cost than existing canary crafting approaches.

隐私审计蜜罐构造差分隐私成员推断

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。