日本フィジカルAI新聞

世界のフィジカルAIを、日本語で。

週刊ニュースレター購読
プライバシーarXiv:2609.13499

銀行の中のカナリア:Private Evolutionにおけるユーザーレベルプライバシーの監査

Canaries in the Bank: Auditing User-Level Privacy in Private Evolution

シェア:XThreadsFacebookLINEはてブBluesky

Private Evolutionの連合学習において、共有候補バンクを操作する攻撃を実証的に監査し、形式的な最悪ケースの差分プライバシー保証と実際に達成可能な漏洩のギャップを定量化した。

著者: Sai Aparna Aketi, Enayat Ullah, Shripad Gade

分類: cs.CR, cs.AI, cs.LG

原文アブストラクト

Private Evolution (PE) generates high-fidelity synthetic data in federated settings without exposing users' raw data. It aggregates clipped user votes over a shared candidate bank into a differentially private histogram, with noise calibrated to the worst-case user contribution. However, it is unclear whether an adversary can realize this worst-case privacy loss while following the PE protocol. We introduce a protocol-aware empirical audit in which the server commits to a single shared candidate bank and replaces roughly 1% of its entries with probes derived from a known, non-private canary. We evaluate eight attacks, including an unchanged-bank baseline, exact copies, plausible paraphrases, and high-entropy synthetic nonces. Experiments on Yelp and Sentiment140 show that natural-text attacks remain substantially below the theoretical DP bound, while nonce-based attacks yield considerably stronger bounds and come closest to the mechanism's privacy ceiling. These results quantify the gap between formal worst-case privacy and leakage achievable through protocol-valid candidate-bank manipulation.

関連論文