高级检索

    基于波动性的机器学习表格数据隐私风险评估框架

    A Fluctuation-Oriented Privacy Risk Assessment Framework for Tabular Data in Machine Learning

    • 摘要: 机器学习模型在利用训练数据提升预测性能的同时,也可能记忆个体样本信息,面临成员推理和重识别等隐私威胁。现有的机器学习隐私风险评估方法通常侧重于模型级全局结果,难以反映表格数据在不同数据子集和不同数据属性之间的局部差异。针对上述问题,提出基于波动性的机器学习表格数据隐私风险评估框架:在数据子集维度,利用密度聚类和结构离群评分划分训练样本,并通过成员推理攻击识别更容易与非成员样本区分的数据子集;在数据属性维度,通过对各待评估属性进行随机置乱,量化其与敏感标签之间的统计依赖,识别与敏感标签具有较强统计依赖的属性。进一步提出综合隐私脆弱性评分OPVS(overall privacy vulnerability score),融合全局成员推理攻击性能以及数据子集和数据属性2个局部维度的结果波动性。基于3个表格数据集和3种机器学习模型的实验表明,不同数据子集的成员推理攻击结果和不同数据属性与敏感标签之间的统计依赖均存在明显差异。实验中噪声子集上的成员推理攻击受试者工作特征曲线下面积(area under the receiver operating characteristic curve,AUC)较核心、边界和随机子集的总体均值高约0.133。所提框架能够识别可能被全局指标掩盖的高成员风险数据子集,以及与敏感标签具有较强统计依赖的属性,为表格数据隐私风险评估提供多粒度分析视角。

       

      Abstract: Machine learning models improve prediction by learning from training data, but they may also retain information about individual samples, thereby exposing the data to membership inference and re-identification risks. Existing privacy assessments commonly report model-level results and may overlook differences across subsets and attributes in tabular data. We propose a fluctuation-oriented framework that examines these differences along two local dimensions while retaining a global assessment. At the data-subset level, HDBSCAN and a structural outlier score are used to divide training samples into core, boundary, and noise subsets; an equally sized random subset is included for comparison. Membership inference attacks then quantify how readily each subset can be distinguished from non-member samples. At the data-attribute level, random-forest prediction, together with repeated attribute permutation, is used to measure the statistical dependence between each evaluated attribute and the sensitive label. Quasi-identifiers serve as the evaluated attributes. The overall privacy vulnerability score (OPVS) combines global membership inference performance with fluctuations across the two local dimensions. Experiments on three tabular datasets and three machine learning models reveal clear local differences. Across nine dataset-model settings, the mean area under the receiver operating characteristic curve (AUC) for membership inference on noise subsets exceeds the aggregate mean for core, boundary, and random subsets by approximately 0.133. These results indicate that global metrics can obscure training regions that are more readily distinguished from non-member samples and attributes that exhibit stronger statistical dependence on sensitive labels, while the framework supports privacy assessment at multiple levels of granularity.

       

    /

    返回文章
    返回