提出无需模型访问的隐私审计框架,区分真实泄露与偶然生成。
Phantoms and Disclosures: A Statistical Framework for Auditing Privacy in Synthetic Data
- 通过统计检验区分真实泄露和偶然生成的数据
- 在不依赖模型的情况下检测隐私泄露,结果比已有方法更严格
- 适用于任意合成数据生成方法,计算成本极低
生成式AI和大语言模型的快速发展推动了合成数据作为敏感真实数据集的隐私保护替代方案。然而,高实用性合成数据常存在记忆并重现训练语料中私密信息的风险。本文提出一种可定制的实证审计框架,用于检测和解释此类数据泄露。该框架引入机制区分“真实泄露”(直接复现用户信息)与“幻象泄露”(偶然生成用户数据)。通过将输入数据划分为训练集与保留集,并应用严格的统计假设检验,判断观测到的泄露是否符合零学习或特定差分隐私(DP)基准。关键优势在于:无需模型访问、无需植入蜜罐、无需参考模型训练——仅需合成输出与保留控制集。实验表明,该方法可有效充当成员推断攻击,提供比现有基于数据的审计方法更紧的隐私泄露下界。本方法具有模型无关性,适用于任何合成数据生成机制,且计算资源需求远低于影子模型或蜜罐类方法。
原文摘要 · Abstract (English)
The rapid adoption of generative AI and Large Language Models (LLMs) has spurred interest in synthetic data as a privacy-preserving alternative to sensitive real-world datasets. However, generating high-utility synthetic data often carries the risk of memorizing and regurgitating private information from the training corpus. In this work, we present a customizable empirical auditing framework designed to detect and explain such data disclosures. Our framework introduces a mechanism to distinguish between "true disclosures"-where the system directly reproduces a user's information-and "phantom disclosures''-where the system incidentally generates a user's data. By partitioning input data into training and holdout sets and applying rigorous statistical hypothesis testing, we determine if observed disclosures are consistent with strict privacy baselines, such as zero-learning or specific Differential Privacy (DP) bounds. Crucially, this approach requires no model access, no canary insertion, and no reference model training -only the synthetic output and a held-out control set. We demonstrate that this framework effectively functions as a membership inference attack, providing empirical lower bounds on privacy leakage that are tighter than prior data-based auditing methods. Our approach is model-agnostic, applies to any synthetic data generation mechanism, and requires orders of magnitude fewer computational resources than shadow-model or canary-based alternatives.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。