arXiv:2607.07209cs.CRcs.LG2026-07

提出可审计的隐私保护机制,实现单次编辑下的持续学习隐私保障。

Continual Learning With Participation Privacy: An Auditable Buffering-Aggregation Recipe

  • 用随机缓冲区将动态数据流转为分块更新,降低隐私泄露风险。
  • 证明了在特定条件下,标准隐私方法可推广至自适应输入场景。
  • 明确隐私与延迟的权衡关系,适合高隐私需求的联邦学习应用。

现代联邦学习和流式学习系统常发布中间模型,因此隐私需在自适应交互下对完整轨迹成立。受参与隐私启发,本文研究单次编辑邻近用户流:一次插入或删除会改变所有后续更新,导致传统汉明距离分析失效。我们提出一种可审计的模块化方案:随机缓冲包装器生成大小为 $[U,2U]$ 的数据块,将单次编辑流转化为每块内类似汉明距离的更新流,并提供显式的积压/延迟保证,其中 $U$ 由隐私参数 $(\varepsilon,δ)$ 决定。进一步证明了一个认证定理,指出非自适应汉明邻居差分隐私证明何时能推广至自适应输入:该连续原语必须使用每轮独立随机性,且在共同自适应上下文中具备稳定的一轮隐私特性。结合上述设计,仅使用标准原语(如树前缀和)即可实现单次编辑流的轨迹级 $(\varepsilon,δ)$-差分隐私,且通过 $U$ 显式关联隐私与延迟。

原文摘要 · Abstract (English)

Modern federated and streaming learning systems often release intermediate models, so privacy must hold for the full trajectory under adaptive interaction. Motivated by participation privacy, we study single-edit neighboring user streams, where one insertion/deletion shifts all subsequent updates and defeats standard Hamming-neighbor continual-release analyses. We give an auditable modular recipe. A randomized buffering wrapper emits bins of size $[U,2U]$, reducing single-edit streams to a Hamming-style per-bin update stream with explicit backlog/delay guarantees, where $U$ is calibrated by the privacy parameters $(\varepsilon,δ)$. We then prove a certification theorem identifying when a non-adaptive Hamming-neighbor DP proof for a continual primitive lifts to adaptive inputs: the primitive must use fresh per-round randomness and have a stable one-round privacy profile under common adaptive context. Together, these ingredients yield trajectory-level $(\varepsilon,δ)$-DP for single-edit streams using standard primitives (e.g., tree prefix sums), with an explicit privacy--latency link via $U$.

隐私保护持续学习差分隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。