We investigate semantic guarantees of private learning algorithms for their resilience to training Data Reconstruction Attacks (DRAs) by informed adversaries. To this end, we derive non-asymptotic minimax lower bounds on the adversary's reconstruction error against learners that satisfy differential privacy (DP) and metric differential privacy (mDP). Furthermore, we demonstrate that our lower bound analysis for the latter also covers the high dimensional regime, wherein, the input data dimensionality may be larger than the adversary's query budget. Motivated by the theoretical improvements conferred by metric DP, we extend the privacy analysis of popular deep learning algorithms such as DP-SGD and Projected Noisy SGD to cover the broader notion of metric differential privacy.
翻译:我们研究隐私学习算法在面对知情对手时对训练数据重构攻击(DRA)的语义保证。为此,我们推导了对于满足差分隐私(DP)和度量差分隐私(mDP)的学习器,对手重构误差的非渐近极小化下界。此外,我们证明针对后者的下界分析同样适用于高维情形,即输入数据维度可能超过对手的查询预算。受度量差分隐私理论优势的启发,我们将主流深度学习算法(如DP-SGD和投影噪声SGD)的隐私分析扩展至更广泛的度量差分隐私概念。