Trade-offs and Guarantees of Adversarial Representation Learning for Information Obfuscation
Han Zhao, Jianfeng Chi, Yuan Tian, Geoffrey J. Gordon
摘要
Crowdsourced data used in machine learning services might carry sensitive information about attributes that users do not want to share. Various methods have been proposed to minimize the potential information leakage of sensitive attributes while maximizing the task accuracy. However, little is known about the theory behind these methods. In light of this gap, we develop a novel theoretical framework for attribute obfuscation. Under our framework, we propose a minimax optimization formulation to protect the given attribute and analyze its inference guarantees against worst-case adversaries. Meanwhile, it is clear that in general there is a tension between minimizing information leakage and maximizing task accuracy. To understand this, we prove an information-theoretic lower bound to precisely characterize the fundamental trade-off between accuracy and information leakage. We conduct experiments on two real-world datasets to corroborate the inference guarantees and validate this trade-off. Our results indicate that, among several alternatives, the adversarial learning approach achieves the best trade-off in terms of attribute obfuscation and accuracy maximization.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper9
- Generalized Demographic Parity for Group FairnessZhimeng Jiang, Xiaotian Han, Chao Fan, Fan Yang 等ICLR 2022 · 被引用 71 次
- Understanding and Mitigating Accuracy Disparity in RegressionJianfeng Chi, Yuan Tian, Geoffrey J. Gordon, Han ZhaoICML 2021 · 被引用 29 次
- Task-Agnostic Privacy-Preserving Representation Learning for Federated Learning against Attribute Inference AttacksCaridad Arroyo Arevalo, Sayedeh Leila Noorbakhsh, Yun Dong, Yuan Hong 等AAAI 2024 · 被引用 26 次
- Posthoc privacy guarantees for collaborative inference with modified Propose-Test-ReleaseAbhishek Singh, Praneeth Vepakomma, Vivek Sharma, Ramesh RaskarNeurIPS 2023 · 被引用 16 次
- Efficient Utility-Preserving Machine Unlearning with Implicit Gradient SurgeryShiji Zhou, Tianbai Yu, Zhi Zhang, Heng Chang 等NeurIPS 2025 · 被引用 6 次
它引用的顶会 Paper2
相关 Paper
- Learning Robust and Privacy-Preserving Representations via Information TheoryBinghui Zhang, Sayedeh Leila Noorbakhsh, Yun Dong, Yuan Hong 等AAAI 2025 · 被引用 4 次
- Information Obfuscation of Graph Neural NetworksPeiyuan Liao, Han Zhao, Keyulu Xu, Tommi S. Jaakkola 等ICML 2021 · 被引用 38 次
- The Fundamental Limits of Least-Privilege LearningTheresa Stadler, Bogdan Kulynych, Michael Gastpar, Nicolas Papernot 等ICML 2024 · 被引用 3 次
- Information Laundering for Model PrivacyXinran Wang, Yu Xiang, Jun Gao, Jie DingICLR 2021 · 被引用 24 次
- CLOAK: Contrastive Guidance for Latent Diffusion-Based Data ObfuscationXin Yang, Omid ArdakanianUbiComp 2026
