跳到正文
原文
arXiv:cs.LG(机器学习,全量分类)· Georgi Ganev, Emiliano De Cristofaro·· 17 小时前AI 评分45

合成数据匿名性主张再审视:从模型中心隐私攻击视角出发

Rethinking Anonymity Claims in Synthetic Data Generation: A Model-Centric Privacy Attack Perspective

AI 导读

论文提出应从模型中心视角重新审视合成数据的匿名性主张,认为有意义的评估必须考虑底层生成模型并基于最新隐私攻击。研究将 GDPR 的个人数据与匿名化定义映射到不同威胁场景下的隐私攻击,指出仅靠合成数据技术不足以保证充分匿名化。对比差分隐私(DP)与基于相似性的隐私指标(SBPMs)后认为,DP 可提供稳健保护,而 SBPMs 缺乏足够保障。

正文

View PDF HTML (experimental)

Abstract:Training generative machine learning models to produce synthetic tabular data has become a popular approach for enhancing privacy in data sharing. As this typically involves processing sensitive personal information, releasing either the trained model or generated synthetic datasets can still pose privacy risks. Yet, recent research, commercial deployments, and privacy regulations like the General Data Protection Regulation (GDPR) largely assess anonymity at the level of an individual dataset.
In this paper, we rethink anonymity claims about synthetic data from a model-centric perspective, arguing that meaningful assessments must account for the underlying generative model and be grounded in state-of-the-art privacy attacks. This perspective better reflects real-world deployments, where trained models are often accessible for interaction or querying. We interpret the GDPR's definitions of personal data and anonymization under such access assumptions to identify the identifiability risks that must be mitigated and map them to privacy attacks across threat settings. We then argue that synthetic data techniques alone do not ensure sufficient anonymization. Finally, we compare the two mechanisms most commonly used with synthetic data -- Differential Privacy (DP) and Similarity-based Privacy Metrics (SBPMs) -- and argue that while DP can offer robust protections against identifiability risks, SBPMs lack adequate safeguards. Overall, our work connects regulatory notions of identifiability with model-centric privacy attacks, enabling more responsible and trustworthy assessment of synthetic data systems by researchers, practitioners, and policymakers.
Comments: Published in the Proceedings of the 25th Workshop on Privacy in the Electronic Society, WPES 2026, part of ACM CCS 2026
Subjects: Cryptography and Security (cs.CR); Computers and Society (cs.CY); Machine Learning (cs.LG)
Cite as: arXiv:2601.22434 [cs.CR]
  (or arXiv:2601.22434v2 [cs.CR] for this version)
  https://doi.org/10.48550/arXiv.2601.22434

arXiv-issued DOI via DataCite

Submission history

From: Georgi Ganev [view email]
[v1] Fri, 30 Jan 2026 00:57:41 UTC (702 KB)
[v2] Thu, 1 Oct 2026 13:32:26 UTC (704 KB)

来源:arXiv:cs.LG(机器学习,全量分类) · arxiv.org