כתבה
arXiv cs.LG ·
כיול רעש סגור נגד השתייכות אינפרנס
Closed-Form Noise Calibration Against Membership Inference for Random-Allocation DP-SGD
חוקרים פיתחו נוסחה חדשה לכיול רעש נגד השתייכות אינפרנס באלגוריתם DP-SGD. הנוסחה מאפשרת קביעת רמת רעש מדויקת יותר, ובכך משפרת את ביצועי האלגוריתם.
תקציר מקורי באנגליתarXiv:2610.09651v1 Announce Type: new Abstract: DP-SGD protects training data by adding Gaussian noise to clipped gradients. The amount of noise is usually chosen by running a numerical privacy accountant inside a search. We study DP-SGD with random allocation, where each epoch uses every record once, at a randomly chosen step. For this setting we give a one-line formula that bounds the accuracy of every membership inference attack (MIA) on the trained model. With $M$ steps per epoch, $E$ epochs and noise multiplier $\sigma$, and with membership and non-membership equally likely a priori, the attack accuracy is at most $\frac12+\frac14\sqrt{(1+(e^{1/\sigma^2}-1)/M)^E-1}$. The formula comes from the chi-square divergence between a Gaussian distribution and a Gaussian mixture that dominates
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית