arXiv:2606.09582cs.LGstat.ML2026-06

提出在高斯差分隐私中选择μ参数的合理方法,便于实际应用。

On Choosing the $μ$ Parameter in Gaussian Differential Privacy

  • 通过匹配强敌手成员推断攻击的性能,建立纯差分隐私ε到高斯差分隐私μ的映射
  • 给出不同ε值对应的μ值表,推荐μ≈ε/5作为保守通用转换
  • 适用于关注隐私保障可解释性的机器学习研究者

近期工作主张在隐私保护机器学习中使用高斯差分隐私(GDP)报告隐私保证。本文通过匹配强敌手在成员推断攻击中的最坏情况表现,基于三个指标:固定误报率下的乘法优势、固定召回率下的精确率、以及标准隐私轮廓,提供了从纯差分隐私ε到高斯差分隐私μ的合理映射。我们给出了一个实用参数范围内的μ值表格,并推荐μ≈ε/5作为保守的通用转换方案。

原文摘要 · Abstract (English)

Recent work argues for using Gaussian differential privacy (GDP) to report the privacy guarantees in privacy-preserving machine learning. We provide principled mappings from pure-DP $\varepsilon$ to GDP $μ$ by matching the worst-case success of a strong-adversary membership inference attack in terms of three metrics: multiplicative advantage at fixed FPR, precision at fixed recall, and the standard privacy profile. We tabulate $μ$ values across a useful range of parameters and recommend $μ\approx \varepsilon/5$ as a conservative general-purpose conversion.

差分隐私高斯隐私参数选择

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。