提出可提升实际隐私的轻量级防御框架,不牺牲理论隐私保障。
Revisiting the Provable-Auditable Privacy Gap of DP-SGD

- 将实证隐私下界作为优化目标,设计通用防御框架。
- 在标准数据集上显著提升模型实证隐私,且不降低理论隐私保证。
- 适用于多种攻击构造、模型与数据集,兼容性好。
差分隐私(DP)传统上用于为算法对训练数据变化的稳定性提供理论上限。在现代私有机器学习应用中,实现效用与理论隐私间的良好权衡极具挑战性,因此人们可能乐观认为现有理论隐私分析过于保守。近期隐私审计研究从另一视角出发,通过构建经验区分事件来下界化算法的真实隐私。现有文献表明,对于现代机器学习中的主流私有训练方法 DP-SGD,其理论隐私界限存在严重松散,已在多种威胁模型下接近匹配的实证下界 [NHSBTJCT23, AC24, CBP25]。本文提出将算法的实证隐私下界作为一个可优化的具体指标,与理论上限互补。我们设计了一种轻量级防御框架,可通用地增强机器学习流水线中的优化方法,在标准基准上实现显著提升的实证隐私。此外,我们证明该框架在增强 DP-SGD 时无需付出理论隐私代价,与此前针对成员推断攻击的防御方案不同。我们在广泛多样的审计构造、模型和数据集上评估了该防御,验证了其灵活性。
原文摘要 · Abstract (English)
Differential privacy (DP) has traditionally been used to provide theoretical upper bounds on an algorithm's stability to changing its training data. In modern private machine learning applications, achieving strong tradeoffs between utility and theoretical privacy is challenging, and thus one may optimistically hope that existing theoretical privacy analyses are loose. Recent work on privacy auditing has adopted a dual viewpoint, instead lower bounding the true privacy of an algorithm by constructing empirical distinguishing events. The auditing literature has thus far yielded a pessimistic outlook on the looseness of theoretical privacy bounds for DP-SGD, the de facto private training method in modern ML, as nearly-matching empirical lower bounds have been achieved under various threat models [NHSBTJCT23, AC24, CBP25]. In this work, we propose the empirical privacy lower bound of an algorithm as a concrete metric to optimize for, complementary to the theoretical upper bound. We give a lightweight defense framework that generically augments optimization methods in the ML pipeline to have significantly-improved empirical privacy on standard benchmarks. Moreover, we show that our framework comes at no theoretical privacy cost when augmenting DP-SGD, unlike previously-proposed defenses against membership inference attacks. We evaluate our defense against a broad range of audit constructions, models, and datasets to demonstrate its flexibility.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。