arXiv:2607.14607cs.LGcs.AI2026-07

首次揭示公平算法对子群体隐私风险的影响差异

Auditing Fairness-Privacy Trade-offs: Subpopulation-Level Effects of Fairness-Enhancing Algorithms

论文配图:Auditing Fairness-Privacy Trade-offs: Subpopulation-Level Effects of Fairness-Enhancing Algorithms
图 1 · 摘自论文原文
  • 用改进的似然比攻击法审计子群体隐私风险
  • 发现公平干预对不同子群体隐私影响不均
  • 适合关注公平与隐私权衡的研究者和从业者

在医疗、执法和金融等敏感领域部署的机器学习模型,需同时满足性能、公平性和隐私性要求。现有研究多关注隐私保护技术对公平性的影响,而忽视了公平增强算法如何影响隐私泄露。本文首次系统研究公平干预对子群体层面成员推理攻击风险的影响。通过改进似然比攻击(LiRA)用于子群审计,揭示了聚合评估所掩盖的隐私差异。进一步分析差分隐私(DP)与不同公平方法的交互关系,发现DP的隐私保护效果和效用代价在子群体间分布不均。结果表明,公平干预并非统一增加隐私风险,其影响取决于模型架构、子群体规模和缓解策略。研究强调应在子群体层面联合评估公平性、隐私性和性能,并提出首个支持实际审计的统一实证框架。

原文摘要 · Abstract (English)

Machine learning (ML) models deployed in sensitive domains such as healthcare, law enforcement, and finance must satisfy not only utility requirements but also fairness and privacy guarantees. While prior work has largely examined how privacy-preserving techniques affect fairness, the inverse question-how fairness-enhancing algorithms influence privacy leakage-remains underexplored. We present the first comprehensive study of how fairness interventions affect membership inference privacy risks at the subpopulation level. By adapting the Likelihood Ratio Attack (LiRA) for subgroup auditing, we uncover privacy disparities that aggregate evaluations obscure. We further analyze how Differential Privacy (DP) interacts with fairness-enhancing methods across different categories, showing that DP's privacy benefits and utility costs are unevenly distributed across subpopulations. Our results demonstrate that fairness interventions do not uniformly increase privacy risk; their impact depends on model architecture, subgroup size, and mitigation strategy. These findings reveal that fairness, privacy, and utility must be jointly evaluated at the subpopulation level, and we introduce the first unified empirical framework to support such auditing in practice.

公平性隐私保护子群体

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。