Differentially Private Distributed Learning

被引:10
作者
Zhou, Yaqin [1 ]
Tang, Shaojie [2 ]
机构
[1] Nanyang Technol Univ, Singapore 639798, Singapore
[2] Univ Texas Dallas, Richardson, TX 75080 USA
关键词
differential privacy; distributed deep learning; SVRG; optimization;
D O I
10.1287/ijoc.2019.0912
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The rich data used to train learning models increasingly tend to be distributed and private. It is important to efficiently perform learning tasks without compromising individual users' privacy even considering untrusted learning applications and, furthermore, understand how privacy-preservation mechanisms impact the learning process. To address the problem, we design a differentially private distributed algorithm based on the stochastic variance reduced gradient (SVRG) algorithm, which prevents the learning server from accessing and inferring private training data with a theoretical guarantee. We quantify the impact of the adopted privacy-preservation measure on the learning process in terms of convergence rate, by which it indicates noises added at each gradient update results in a bounded deviation from the optimum. To further evaluate the impact on the trained models, we compare the proposed algorithm with SVRG and stochastic gradient descent using logistic regression and neural nets. The experimental results on benchmark data sets show that the proposed algorithm has minor impact on the accuracy of trained models under a moderate amount of privacy budget.
引用
收藏
页码:779 / 789
页数:11
相关论文
共 24 条
[1]   Deep Learning with Differential Privacy [J].
Abadi, Martin ;
Chu, Andy ;
Goodfellow, Ian ;
McMahan, H. Brendan ;
Mironov, Ilya ;
Talwar, Kunal ;
Zhang, Li .
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, :308-318
[2]  
Acs Gergely, 2011, Information Hiding. 13th International Conference, IH 2011. Revised Selected Papers, P118, DOI 10.1007/978-3-642-24178-9_9
[3]   Investigation of the conformational dynamics of the apo A2A adenosine receptor [J].
Caliman, Alisha D. ;
Swift, Sara E. ;
Wang, Yi ;
Miao, Yinglong ;
McCammon, J. Andrew .
PROTEIN SCIENCE, 2015, 24 (06) :1004-1012
[4]  
Castelluccia C, 2005, PROCEEDINGS OF MOBIQUITOUS 2005, P109
[5]   Distributed Learning to Protect Privacy in Multi-centric Clinical Studies [J].
Damiani, Andrea ;
Vallati, Mauro ;
Gatta, Roberto ;
Dinapoli, Nicola ;
Jochems, Arthur ;
Deist, Timo ;
van Soest, Johan ;
Dekker, Andre ;
Valentini, Vincenzo .
ARTIFICIAL INTELLIGENCE IN MEDICINE (AIME 2015), 2015, 9105 :65-75
[6]  
Deist TM, 2017, CLIN TRANSL RAD ONCO, V4, P24, DOI 10.1016/j.ctro.2016.12.004
[7]  
Dwork C, 2006, LECT NOTES COMPUT SC, V4004, P486
[8]   Calibrating noise to sensitivity in private data analysis [J].
Dwork, Cynthia ;
McSherry, Frank ;
Nissim, Kobbi ;
Smith, Adam .
THEORY OF CRYPTOGRAPHY, PROCEEDINGS, 2006, 3876 :265-284
[9]  
Dwork C, 2009, ACM S THEORY COMPUT, P371
[10]  
Dwork Cynthia, 2006, Differential privacy, P1