arXiv:2608.07913cs.CRcs.AI2026-08

为联邦生成系统提供可随时验证的隐私保护风险认证,确保输出可靠性。

Private Anytime Selective-Risk Certification for Federated Retrieval-Augmented Generation: Guarantees and Empirical Limits

  • 基于高斯噪声的统计量传递,实现无模型依赖的风险认证
  • 在200次实验中未出现风险越界,即使在私密性较强时仍有效
  • 适合对安全性要求高的生成系统部署,尤其适用于敏感数据场景

选择性风险证书保证通过的输出符合预设误差目标。我们提出Fed-SRC,一种针对联邦、差分隐私、自适应监控的检索增强生成系统的无模型风险证书。客户端仅发布经过高斯扰动的得分与损失直方图。基于记录索引和噪声方差索引的鞅方法,联合约束目标风险对比与接受样本比例,在所有注册阈值与轮次下实现可预测的招募、退出、阈值选择与可选停止。一个范围一的总变差项将校准混合分布转移至声明的部署混合分布。贡献在于该私密、联邦、任意时刻组合机制,而非对比统计量或接受下限本身。实证上,所有评估条件(包括不同隐私水平与策略)均未出现联合边界违反。运行效能依赖于得分分布与群体特性:主目标r*=0.10从未被认证;在RAGTruth上次级目标r*=0.20也未被认证;而在HaluEval问答任务中,非私密试验全部200次均成功认证,且保留风险低于目标。朴素私有化非私密证书在200次试验中有146至198次违反边界。作为探索性对比,我们也评估了一种私有投注资本启发式方法,但未建立其e过程有效性。该启发式在ε≤4时停止认证,而Fed-SRC仍可持续认证。认证过程消耗约30倍于校准样本数的流事件。

原文摘要 · Abstract (English)

Selective-risk certificates promise that accepted outputs meet a declared error target. We develop Fed-SRC, a score-agnostic certificate for federated, differentially private, adaptively monitored retrieval-augmented generation. Clients release only Gaussian-perturbed score and loss histograms. Record-indexed and noise-variance-indexed martingales jointly bound target-risk contrast and accepted mass over all registered thresholds and rounds, permitting predictable recruitment, dropout, threshold selection, and optional stopping. A range-one total-variation term transfers the calibration mixture to a declared deployment mixture. The contribution is this private, federated, anytime combination, rather than the contrast statistic or acceptance floor individually. Empirically, no simultaneous-bound violation occurs in any evaluated cell, privacy level, or policy. Operational power depends on the score and population: the primary target r*=0.10 never certifies, and on RAGTruth the secondary target r*=0.20 never certifies either, whereas on HaluEval question answering it certifies in all 200 non-private trials, with held-out risk below the target. Naively privatized non-private certificates violate their bounds in 146 to 198 of 200 trials. As an exploratory comparison, we also evaluate a private betting-capital heuristic for which we do not establish e-process validity. This heuristic stops certifying at epsilon <= 4, where Fed-SRC still certifies. Certification nevertheless consumes roughly 30 times more stream events than unique calibration items.

联邦学习隐私保护风险认证生成模型

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。