arXiv論文メモ
新着一覧
cs.CR / cs.CL · 査読状況未確認

公開文書からの個人特定リスクを統計的に較正

Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees

Shuo Huang, Gholamreza Haffari, Xingliang Yuan, Ting Yu, Lizhen Qu

この論文をやさしく読む

ひとことで言うと

公開文章が誰のものかをAIが絞り込む際、候補者集合を統計的に較正して、個人特定されやすさを評価する方法です。

何に役立つ?

考えられる用途は、公開する文書の匿名性を、攻撃者が持つ追加情報やモデルの違いごとに監査することです。リスクの比較に統計的な基準を与えます。

この研究の面白いところ

単に攻撃の正答率を見るのではなく、真の人物を含むよう較正した候補集合を作り、その大きさを漏えいの代理指標として使います。

どこまで分かった?

保証は交換可能性の仮定の下での候補集合の被覆に関するものです。集合サイズは漏えいの代理指標であり、任意の攻撃者に対する匿名性や、各文書の条件付き安全性を無条件に保証するものではありません。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

公開テキストからの実証的な身元情報漏えいは、文書と個人を結び付けるために大規模言語モデル(LLM)と補助知識を組み合わせる攻撃者によって、ますます引き起こされている。既存の監査は通常、特定の攻撃処理系の成功率を報告するが、有限標本での統計的保証を欠く。一方、差分プライバシーなどの学習時保護を、個別の自然言語文書の公開時判断へ置き換えるのは難しい。 本研究では、LLMを利用する攻撃者に対し、公開文書ごとに再識別リスクの統計的な証明を与える、分布形を仮定しない較正枠組みConformal Privacy Auditing(CPA)を導入する。CPAは、交換可能性の下で、利用者が選ぶ信頼水準により真の身元を含むことが保証される候補身元のコンフォーマル曖昧性集合を出力する。同時に、集合の大きさから導く解釈可能な漏えいの代理指標も出力する。CPAはロジットへアクセスする攻撃者とサンプリングのみの攻撃者の両方に対応し、オープンソースモデルと非公開APIモデルを統一した枠組みで監査できる。複数の公開ベンチマークと攻撃者構成にわたって、CPAは較正された被覆率を達成し、補助知識、LLMによる増強、公開機構の変化に伴う、統計的に保証された識別可能性の急激な変化を明らかにする。これにより、攻撃者構成、データセット、公開機構をまたいで公開時の紐付けリスクを報告・比較する、統計的根拠を提供する。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-18(UTC)
最新改訂
2026-09-18 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Empirical identity leakage from released text is increasingly driven by attackers that combine large language models (LLMs) with auxiliary knowledge to link documents to individuals. Existing audits typically report success rates for specific attack pipelines but lack finite-sample statistical guarantees, while training-time protections such as differential privacy are difficult to translate into release-time decisions for individual natural-language documents. We introduce Conformal Privacy Auditing(CPA), a distribution-free calibration framework that provides a statistical certificate of re-identification risk for each released document against LLM-empowered adversaries. CPA outputs a conformal ambiguity set of candidate identities that is guaranteed to contain the true identity with user-chosen confidence under exchangeability, together with an interpretable leakage proxy derived from set size. CPA supports both logit-access and sampling-only attackers, enabling audits of open-source models and proprietary API models in a unified framework. Across multiple release benchmarks and attacker configurations, CPA achieves calibrated coverage and reveals sharp shifts in certified identifiability as auxiliary knowledge, LLM augmentation, and release mechanisms vary, providing a statistically grounded basis for reporting and comparing release-time linkage risk across attacker configurations, datasets, and release mechanisms alike.

arXiv ID: 2609.21340 / 要約の誤りについて