用高斯过程后验采样实现隐私保护,无需额外加噪。
Differential Privacy of Gaussian Process Posterior Sampling

- 利用后验采样固有随机性提供差分隐私保证
- 正则化程度直接影响隐私效果,方差与样本数也起关键作用
- 适合关注数据隐私的机器学习研究者,尤其在敏感数据建模场景
我们研究当训练集(含特征和响应)为私密时,释放高斯过程后验样本路径的隐私性。与传统添加外部噪声的差分隐私机制不同,后验采样本身具有随机性。本文通过推导后验样本路径释放的显式瑞尼差分隐私边界,证明这种内在随机性可提供差分隐私保障。边界将后验均值泄漏与依赖数据的后验协方差泄漏分离,表明有意义的隐私性强烈依赖于有效岭正则化。通过成员推断攻击验证了经验泄漏与正则化、后验方差及释放样本路径数量的预测关系。下游后验采样任务的效用实验表明,在存在噪声观测的场景下,兼容隐私的正则化可在小幅损失效用的前提下保留有用决策。当需要更强隐私时,可通过添加校准后的高斯过程噪声进一步强化内在隐私保障,提供明确的隐私调节机制。
原文摘要 · Abstract (English)
We study the privacy of releasing posterior sample paths from a Gaussian process (GP) when the entire training set including covariates and responses is private. Unlike standard differential-privacy (DP) mechanisms that add external noise, posterior sampling is random by construction. We show that this intrinsic randomness yields DP guarantees by deriving explicit Rényi-DP bounds for GP posterior sample-path release. The bounds separate posterior-mean leakage from data-dependent posterior-covariance leakage showing that meaningful privacy depends sharply on effective ridge regularisation. We apply membership-inference attacks to show that empirical leakage follows the predicted dependence on regularisation, posterior variance and the number of released posterior sample-paths. Utility experiments on downstream posterior-sampling tasks identify noisy-observation regimes where privacy-compatible regularisation preserves useful decisions with modest utility loss. When stronger privacy is needed, the intrinsic guarantee can be sharpened by adding calibrated GP noise, providing an explicit additional privacy knob.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。