引用本文:王树兰,邱瑶,赵陈斌,邹家须,王彩芬.eDPRF: 高效的差分隐私随机森林训练算法.软件学报,2025,36(7):2929-2946
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 1394次   下载 2293 本文二维码信息
码上扫一扫!
分享到: 微信 更多
eDPRF: 高效的差分隐私随机森林训练算法
王树兰1, 邱瑶1, 赵陈斌2, 邹家须1, 王彩芬1
1.深圳技术大学 大数据与互联网学院, 广东 深圳 518118;2.空天信息安全与可信计算教育部重点实验室 (武汉大学 国家网络安全学院), 湖北 武汉 430072
摘要:
差分隐私凭借其强大的隐私保护能力被应用在随机森林算法解决其中的隐私泄露问题, 然而, 直接将差分隐私应用在随机森林算法会使模型的分类准确率严重下降. 为了平衡隐私保护和模型准确性之间的矛盾, 提出了一种高效的差分隐私随机森林训练算法eDPRF (efficient differential privacy random forest). 具体而言, 该算法设计了决策树构建方法, 通过引入重排翻转机制高效地查询输出优势, 进一步设计相应的效用函数实现分裂特征以及标签的精准输出, 有效改善树模型在扰动情况下对于数据信息的学习能力. 同时基于组合定理设计了隐私预算分配的策略, 通过不放回抽样获得训练子集以及差异化调整内部预算的方式提高树节点的查询预算. 最后, 通过理论分析以及实验评估, 表明算法在给定相同隐私预算的情况下, 模型的分类准确度优于同类算法.
关键词:  随机森林  差分隐私  隐私预算  重排翻转  扰动方式
DOI:10.13328/j.cnki.jos.007332
分类号:
基金项目:国家自然科学基金(61702341); 深圳技术大学深圳市高等院校稳定支持项目(SZWD2021012); 深圳技术大学研究生校企合作研究基金(20223108010009)
eDPRF: Efficient Differential Privacy Random Forest Training Algorithm
WANG Shu-Lan1, QIU Yao1, ZHAO Chen-Bin2, ZOU Jia-Xu1, WANG Cai-Fen1
1.College of Big Data and Internet, Shenzhen Technology University, Shenzhen 518118, China;2.Key Laboratory of Aerospace Information Security and Trusted Computing of Ministry of Education (School of Cyber Science and Engineering, Wuhan University), Wuhan 430072, China
Abstract:
Differential privacy, owing to its strong privacy protection capacity, is applied to the random forest algorithm to address the privacy leakage problem. However, the direct application of differential privacy to the random forest algorithm leads to a significant decline in the model’s classification accuracy. To balance the contradiction between privacy protection and model accuracy, this study proposes an efficient differential privacy random forest training algorithm, efficient differential privacy random forest (eDPRF). Specifically, the study designs a decision tree construction method based on the permute-and-flip mechanism. By introducing the efficient query output advantage of the permute and flip mechanism, the corresponding utility functions are further designed to achieve the precise output of split features and labels, effectively enhancing the learning ability of the tree model for data information under perturbation circumstances. At the same time, the study designs a privacy budget allocation strategy based on the composition theorem, which improves the privacy budget utilization rate of nodes by obtaining training subsets without replacement sampling and adjusting internal budgets through differentiation. Finally, through theoretical analysis and experimental evaluation, it is demonstrated that the proposed algorithm outperforms similar algorithms in terms of the model’s classification accuracy when given the same privacy budget.
Key words:  random forest  differential privacy  privacy budget  permute and flip  perturbation method

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: