We investigate semantic guarantees of private learning algorithms for their resilience to training Data Reconstruction Attacks (DRAs) by informed adversaries. To this end, we derive non-asymptotic minimax lower bounds on the adversary's reconstruction error against learners that satisfy differential privacy (DP) and metric differential privacy (mDP). Furthermore, we demonstrate that our lower bound analysis for the latter also covers the high dimensional regime, wherein, the input data dimensionality may be larger than the adversary's query budget. Motivated by the theoretical improvements conferred by metric DP, we extend the privacy analysis of popular deep learning algorithms such as DP-SGD and Projected Noisy SGD to cover the broader notion of metric differential privacy.
翻译:我们研究隐私学习算法在面对知情对手时对训练数据重构攻击(DRA)的语义保障。为此,我们针对满足差分隐私(DP)和度量差分隐私(mDP)的学习器,推导了对手重构误差的非渐近极小化下界。此外,我们证明后者下界分析亦可覆盖高维场景——其中输入数据维度可能超过对手的查询预算。受度量差分隐私理论优势的启发,我们将DP-SGD和投影噪声SGD等主流深度学习算法的隐私分析扩展至更广泛的度量差分隐私概念。