arXiv:2608.22607cs.LGcs.CR2026-08

用差分隐私保护金融反欺诈中的解释信息,防止泄露风险。

Mitigating Explanation Leakage in Financial Fraud Detection Systems

  • 对树模型的SHAP值应用客户端级差分隐私,仅保护解释数据。
  • 在IEEE-CIS数据集上保持高精度,同时显著降低成员推断攻击风险。
  • 适合关注隐私与可解释性平衡的金融风控系统研发人员。

金融反欺诈依赖集中式机器学习模型,带来严重数据隐私风险。联邦学习(FL)虽能分散数据处理,但金融监管仍要求模型具备透明性,需使用可解释AI工具如TreeSHAP。然而近期网络安全研究发现,共享高保真度的SHAP解释会暴露联邦网络,面临成员推断攻击(MIAs)。本文提出并评估了DP-FedSHAP,一种新架构:仅对后验TreeSHAP向量施加客户端级差分隐私。与直接扰动模型权重的基线方法对比,基于高度不平衡的IEEE-CIS Fraud Detection数据集,研究衡量了解释保真度、隐私保护与模型精确率-召回率曲线下面积(AUPRC)之间的权衡。

原文摘要 · Abstract (English)

Financial fraud detection relies heavily on centralized machine learning models. This creates serious data privacy risks. Federated Learning (FL) decentralizes data processing, but financial regulations still require models to be transparent. This means using Explainable AI (XAI) tools such as TreeSHAP. Recent cybersecurity research shows a problem with this approach. Sharing high-fidelity SHAP explanations exposes the federated network to Membership Inference Attacks (MIAs). This dissertation proposes and evaluates DP-FedSHAP. It is a new architecture that applies client-level differential privacy only to post-hoc TreeSHAP vectors. It is compared against a Weight-Level DP baseline, which perturbs the trained model directly instead. Using the highly imbalanced IEEE-CIS Fraud Detection dataset, this study measures the trade-off between explanation fidelity, privacy preservation, and the model's Area Under the Precision-Recall Curve (AUPRC).

联邦学习差分隐私可解释AI金融风控

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。