כתבה
arXiv cs.AI ·
A Sharp Transition in Data Reconstruction under Differential Privacy
תקציר מקורי באנגליתarXiv:2609.37344v1 Announce Type: cross Abstract: Data reconstruction attacks have empirically been successful in recovering training samples from learned models, raising privacy concerns and motivating defenses with guarantees that remain valid against future threats. While differential privacy (DP) provides formal protection, choosing the privacy budget remains a challenge: small budgets severely reduce utility, but it is hard to quantify how large the budget can be without allowing accurate reconstruction. In this work, we study informed attackers who aim to reconstruct a single $d$-dimensional training sample from a $\rho$-zero-concentrated DP model, knowing all other training data. Our main contribution is to establish a sharp transition at $\rho \asymp d$ for data reconstruction: on
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית