利用差分隐私的假设检验解释界定数据重构攻击
密码学与安全
2023-07-11 v1 人工智能
摘要
我们探讨重构鲁棒性(ReRo),其近期被提出作为对机器学习模型数据重构攻击成功的上界。先前研究表明差分隐私(DP)机制也提供ReRo,但迄今为止仅给出了紧ReRo界的渐近蒙特卡洛估计。因此,针对一般DP机制可直接计算的ReRo界是值得期待的。本文中,我们建立假设检验DP与ReRo之间的联系,并推导出Laplace和Gaussian机制及其子采样变体的闭式、解析或数值ReRo界。
引用
@article{arxiv.2307.03928,
title = {Bounding data reconstruction attacks with the hypothesis testing interpretation of differential privacy},
author = {Georgios Kaissis and Jamie Hayes and Alexander Ziller and Daniel Rueckert},
journal= {arXiv preprint arXiv:2307.03928},
year = {2023}
}