arXiv:2606.20546cs.LG2026-06

用可预测性量化隐私泄露,更精细地评估攻击者知情下的隐私风险。

Predictability as a Fine-Grained Measure for Privacy

  • 基于攻击者已知数据和查询类型,定义隐私泄露为预测能力的增量提升
  • 在几乎所有个体被泄露时,可推导出互信息意义下的差分隐私保障
  • 适用于需精细化隐私控制的场景,如敏感信息保护与模型输出扰动

差分隐私(DP)虽能提供严格的个体级隐私保障,但其最坏情况特性带来高昂的隐私-精度权衡。本文提出基于可预测性的隐私框架,显式考虑攻击者的先验知识:部分由随机过程生成的数据、已泄露数据集的一部分及特定查询族。该框架将隐私泄露定义为攻击者在观察算法输出后,对未知个体敏感信息预测能力的提升程度,超出其仅从已泄露数据中可推断的部分。我们证明,可预测性与差分隐私在一般情况下不可比较:一方可小而另一方大。但在所有个体除一人外均被泄露、且所有二元查询均视为敏感的最坏情形下,可预测性蕴含互信息差分隐私。更一般地,该框架提供了针对特定敏感信息和攻击者模型的细粒度隐私度量。本文引入广义矩方法(GMM),分析在平稳、遍历、混合过程生成的泄露数据下,渐近可预测性的性质,并据此设计一种用于经验风险最小化(ERM)的可预测性校准输出扰动方案。该方法与差分隐私互补,可协同使用以实现精细化隐私控制。

原文摘要 · Abstract (English)

Differential privacy (DP) ensures rigorous individual-level privacy guarantees against even the most knowledgeable attackers, but its worst-case nature can impose a costly privacy-accuracy tradeoff. We introduce privacy via predictability, a fine-grained framework that explicitly incorporates the attacker's core knowledge, a compromised portion of the dataset generated by a stochastic process, and a specified family of queries. Predictability measures privacy leakage as the incremental gain in an attacker's ability to predict sensitive information about unknown individuals after observing the algorithm's output, beyond what can already be inferred from the compromised data. We show that predictability and DP are generally incomparable: each can be small while the other is large. However, in the worst-case regime where all but one individual is compromised, and all binary queries are considered sensitive, predictability implies mutual-information DP. More generally, predictability provides a finer-grained privacy metric tailored to specific sensitive information and specific attacker models. We introduce a general framework, using the generalized method of moments (GMM), to analyze asymptotic predictability when the compromised data is generated by a stationary, ergodic, mixing process. Using this analysis, we derive a predictability-calibrated output perturbation scheme for ERM. Our approach is complementary to DP and can be used alongside DP to provide fine-grained privacy control.

隐私保护可预测性差分隐私统计学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。