---
格式版本: 2
标题: "Geometric Data Perturbation with Noisy-Anchor Alignment for Privacy-Preserving Collaborative Learning"
原文链接: "https://arxiv.org/abs/2608.18749"
发布日期: "2026-08-19"
发布时间校准状态: "found"
发布时间需复核: "否"
发布时间来源: "rule:local:strict_original_body"
发布时间证据: "**\\[v1\\]** Wed, 19 Aug 2026 09:59:55 UTC (13,479 KB)"
发布时间校准原因: "规则确认唯一严格发布时间，来源 local:strict_original_body"
发布时间校准置信度: "high"
发布时间候选数量: 18
发布时间严格候选数量: 6
发布时间原页读取状态: "source template page reused from URL open"
发布时间未找到原因: ""
发布时间校准时间: "2026-08-20T15:22:37+08:00"
发布时间仲裁状态: "skipped"
发布时间仲裁尝试次数: 0
发布时间仲裁耗时毫秒: 0
发现时间: "2026-08-20T15:18:01+08:00"
入库时间: "2026-08-20T07:22:37.225Z"
来源平台: "arXiv 学术论文搜索"
搜索渠道: "source_template"
搜索词: "https://arxiv.org/search/?query=deployment&searchtype=all"
匹配关键词:
  - "deployment"
  - "performance"
相关厂家:
  []
相关专家:
  []
内容类型: "网页"
抓取工具: "Free Fetch + Defuddle"
清洗工具: "Defuddle Markdown + Defuddle/Readability 正文提取"
原始附件:
  []
AI优质: "否"
AI打分: 0
AI分档: "非优质"
AI质检状态: "不通过"
AI打分理由: "论文主题为隐私保护协作学习中的数据扰动方法，与超节点/AI Rack/机柜级AI基础设施完全无关，未涉及任何相关技术或商业信息。"
AI质检模型: "ali-deepseek-v4-flash"
AI质检时间: "2026-08-20T15:26:01+08:00"
AI主题相关性: 0
AI来源权威性: 0
AI新颖性: 0
AI技术细节: 0
AI商业部署信号: 0
AI完整性: 0
AI摘要: "本文提出在隐私保护协作学习的几何数据扰动方法中，对共享锚表示加噪声而非对私有数据表示加噪声，以避免锚矩阵泄露导致非合作用户数据被精确恢复。"
AI摘要模型: "ali-deepseek-v4-flash"
AI摘要时间: "2026-09-07T03:20:04.848Z"
采集批次: "2026年8月20日14点19分32秒"
采集批次ID: "20260820-141932-079"
去重键: "https://arxiv.org/abs/2608.18749"
---

## Computer Science > Machine Learning

## Title:Geometric Data Perturbation with Noisy-Anchor Alignment for Privacy-Preserving Collaborative Learning

[View PDF](https://arxiv.org/pdf/2608.18749) [HTML (experimental)](https://arxiv.org/html/2608.18749v1)

> Abstract:Geometric Data Perturbation (GDP) enables one-shot, privacy-preserving collaborative learning: each participant applies a distance-preserving transformation to its private data and uploads only the resulting representation to a central analyst. We study GDP under analyst-participant collusion, in which the analyst combines all uploaded representations with the private data and transformations disclosed by colluding participants to recover a non-colluding participant's private data. Participant-specific independent transformations resist this attack but map participants' data into incompatible representation spaces, degrading downstream model performance. Shared-anchor alignment from Data Collaboration (DC) analysis restores compatibility and improves utility, but we show that disclosing the DC anchor matrix enables exact recovery of non-colluding participants' private data even in the presence of collusion. Adding noise directly to the private-data representations mitigates this vulnerability but substantially reduces utility. We propose adding noise to the anchor representations instead. Each participant independently transforms its private data and the shared anchor matrix, perturbs only the resulting anchor representation, and uploads both representations in a single round. Using the noisy anchor representations, the analyst aligns the private-data representations by solving a Generalized Orthogonal Procrustes Problem. We characterize alignment and recovery errors, specialize a conservative sufficient condition for convergence of the alignment to our setting, and analyze three recovery attacks. Experiments on MNIST and CelebA show that, across the evaluated attacks and deployment settings, anchor noise achieves higher learning accuracy than private-data noise at comparable measured leakage, yielding a more favorable privacy-utility trade-off under the specified collusion model.

| Comments: |  |
| --- | --- |
| Subjects: | Machine Learning (cs.LG); Cryptography and Security (cs.CR) |
| Cite as: | [arXiv:2608.18749](https://arxiv.org/abs/2608.18749) \[cs.LG\] |
|  | (or [arXiv:2608.18749v1](https://arxiv.org/abs/2608.18749v1) \[cs.LG\] for this version) |
|  | [https://doi.org/10.48550/arXiv.2608.18749](https://doi.org/10.48550/arXiv.2608.18749) |

## Submission history

From: Akiko Yoshise \[[view email](https://arxiv.org/show-email/ffe5455b/2608.18749)\]  
**\[v1\]** Wed, 19 Aug 2026 09:59:55 UTC (13,479 KB)

[Which authors of this paper are endorsers?](https://arxiv.org/auth/show-endorsers/2608.18749) | Disable MathJax ([What is MathJax?](https://info.arxiv.org/help/mathjax.html))
