Integrally Private Model Selection for Deep Neural Networks

被引:1
作者
Varshney, Ayush K. [1 ]
Torra, Vicenc [1 ]
机构
[1] Umea Univ, Dept Comp Sci, S-90740 Umea, Sweden
来源
DATABASE AND EXPERT SYSTEMS APPLICATIONS, DEXA 2023, PT II | 2023年 / 14147卷
关键词
Data privacy; Integral privacy; Deep neural networks; Privacy-preserving ML;
D O I
10.1007/978-3-031-39821-6_33
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Deep neural networks (DNNs) are one of the most widely used machine learning algorithms. In the literature, most of the privacy related work to DNNs focus on adding perturbations to avoid attacks in the output which can lead to significant utility loss. Large number of weights and biases in DNNs can result in a unique model for each set of training data. In this case, an adversary can perform model comparison attacks which lead to the disclosure of the training data. In our work, we first introduce the model comparison attack for DNNs which accounts for the permutation of nodes in a layer. To overcome this, we introduce a relaxed notion of integral privacy called epsilon-integral privacy. We further provide a methodology for recommending epsilon-Integrally private models. We use a data-centric approach to generate subsamples which have the same class-distribution as the original data. We have experimented with 6 datasets of varied sizes (10k to 7 million instances) and our experimental results show that our recommended private models achieve benchmark comparable utility. We also achieve benchmark comparable test accuracy for 4 different DNN architectures. The results from our methodology show superiority under comparison with three different levels of differential privacy.
引用
收藏
页码:408 / 422
页数:15
相关论文
共 25 条
[21]   Explaining Recurrent Machine Learning Models: Integral Privacy Revisited [J].
Torra, Vicenc ;
Navarro-Arribas, Guillermo ;
Galvan, Edgar .
PRIVACY IN STATISTICAL DATABASES, PSD 2020, 2020, 12276 :62-73
[22]   Maximal c consensus meets [J].
Torra, Vicenc ;
Senavirathne, Navoda .
INFORMATION FUSION, 2019, 51 :58-66
[23]   Integral Privacy [J].
Torra, Vicenc ;
Navarro-Arribas, Guillermo .
CRYPTOLOGY AND NETWORK SECURITY, CANS 2016, 2016, 10052 :661-669
[24]  
Vapnik V. N., 2015, Measures of complexity, P11
[25]  
Vershynin R., 2018, High-dimensional probability: An introduction with applications in data science, V47