Spectrum-Aware Bounds on Invertibility for Privacy-Enhancing Instance Encoding

📅 2026-08-24
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对实例编码隐私保护方法的可逆性问题,提出一种新的谱感知界限方法,该方法更紧致、适用于确定性编码器并扩展到多种相似度量。
📝 Abstract
Instance encoding is a popular empirical technique for privacy enhancement when sharing data to an untrusted server. It transforms sensitive data through an encoding process before sharing, with the hope that the encoding process retains utility but makes it hard to reconstruct the original data. However, most work offers no theoretical guarantee that the encoding process is actually irreversible. A recent work derived a mean-squared error (MSE) bound limiting any adversary's reconstruction accuracy, offering one of the first theoretical results in this domain. This bound, however, has three critical limitations: it is often too loose, only works with randomized encoders (excluding many deterministic encoders practitioners use), and only bounds MSE. We introduce a family of new bounds that (1) are tighter, (2) applicable even to fully deterministic encoders, and (3) can extend beyond MSE to other norm-based similarity metrics, by properly accounting for the encoder's spectral structure. We evaluate our bounds across a range of encoders, datasets, and attacks, showing they hold consistently and improve upon the existing bound.
Problem

Research questions and friction points this paper is trying to address.

instance encoding
privacy enhancement
invertibility
mean-squared error bound
deterministic encoders
Innovation

Methods, ideas, or system contributions that make the work stand out.

Spectrum-Aware Bounds
Invertibility
Privacy-Enhancing
Instance Encoding
Norm-Based Metrics
🔎 Similar Papers
No similar papers found.
S
Seokjin Hwang
The Pennsylvania State University
Y
Yuting Li
The Pennsylvania State University
Kiwan Maeng
Kiwan Maeng
Pennsylvania State University
Privacy-preserving MLsystems for MLcompilersembedded systems