arXiv:2607.13928cs.CRcs.LG2026-07中稿 · ICML

为举报者设计可否认性保障,防止组织通过审计选择识别举报人。

Plausible Deniability Guarantees for Whistleblowers

论文配图:Plausible Deniability Guarantees for Whistleblowers
图 1 · 摘自论文原文
  • 在强敌威胁模型下,对每次审计选择施加(0, δ)差分隐私保护
  • 新机制噪声仅随√logT增长,远优于随机响应方法
  • 适合需要匿名举报的组织内部监督场景

举报者是防范组织不法行为的关键屏障,但报复风险会抑制报告意愿。现有保护方案缺乏形式化隐私保障,而传统差分隐私机制未针对核心威胁模型——即被审计组织观察审计选择并据此识别举报人。本文将对抗强敌威胁的形式化为每条记录的(0, δ)-差分隐私。证明在选择阶段使用随机响应的方法,其性能提升上限仅为δ。随后提出通用机制:将私有审计转化为私有持续计数问题,任意(0, δ)-DP持续计数器经后处理即可复用,审计记录继承相同保障。结合近期持续计数成果,实现每条记录(0, δ)-DP,噪声规模为O(√logT),适用于长度为T的审计周期。效用定理表明,当最常被报告组织与次高者之间的报告差距增长快于√logT时,选择误差趋于零。仿真显示显著优于随机响应。

原文摘要 · Abstract (English)

Whistleblowers are a key safeguard against organizational wrongdoing, but the threat of retaliation deters reporting. Existing whistleblower-protection proposals lack formal privacy guarantees, and existing differential privacy mechanisms do not directly target the natural threat model -- one in which the audited organization itself observes auditor selection decisions and uses them to identify reporters. We formalize protection against a strong-adversary threat model as per-report $(0, δ)$-differential privacy on the transcript of audit selections. Within this framework we prove that a natural approach -- randomized response applied at the selection step -- can never outperform uniform random auditing by more than $δ$ at any horizon. We then give a generic mechanism that reduces private auditing to private continual counting: any $(0, δ)$-DP continual counter plugs in by post-processing, and the audit transcript inherits the same per-report guarantee. Instantiating the reduction with a recent work in continual counting yields per-report $(0, δ)$-DP with noise scaling as $O(\sqrt{\log T})$ across a horizon of $T$ audit decisions. A utility theorem shows that the selection error vanishes whenever the noisy report gap between the most-reported organization and the runner-up grows faster than $\sqrt{\log T}$. Simulations show a substantial improvement over randomized response.

差分隐私举报者保护数据安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。