Deep Learning with Differential Privacy

被引:2980
作者
Abadi, Martin [1 ]
Chu, Andy [1 ]
Goodfellow, Ian [1 ,2 ]
McMahan, H. Brendan [1 ]
Mironov, Ilya [1 ]
Talwar, Kunal [1 ]
Zhang, Li [1 ]
机构
[1] Google, Mountain View, CA 94043 USA
[2] OpenAI, San Francisco, CA USA
来源
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY | 2016年
关键词
D O I
10.1145/2976749.2978318
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Machine learning techniques based on neural networks are achieving remarkable results in a wide variety of domains. Often, the training of models requires large, representative datasets, which may be crowdsourced and contain sensitive information. The models should not expose private information in these datasets. Addressing this goal, we develop new algorithmic techniques for learning and a refined analysis of privacy costs within the framework of differential privacy. Our implementation and experiments demonstrate that we can train deep neural networks with non-convex objectives, under a modest privacy budget, and at a manageable cost in software complexity, training efficiency, and model quality.
引用
收藏
页码:308 / 318
页数:11
相关论文
共 57 条
  • [31] Dwork C, 2009, ACM S THEORY COMPUT, P371
  • [32] Dwork Cynthia, 2016, CORR
  • [33] Model Inversion Attacks that Exploit Confidence Information and Basic Countermeasures
    Fredrikson, Matt
    Jha, Somesh
    Ristenpart, Thomas
    [J]. CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1322 - 1333
  • [34] Goodfellow I., 2015, C o R R , abs/ 1510. 01799v2
  • [35] GRAHAM B, 2014, CORR
  • [36] Gupta A, 2010, PROC APPL MATH, V135, P1106
  • [37] Ierusalimschy R, 1996, SOFTWARE PRACT EXPER, V26, P635, DOI 10.1002/(SICI)1097-024X(199606)26:6<635::AID-SPE26>3.0.CO
  • [38] 2-P
  • [39] What is the Best Multi-Stage Architecture for Object Recognition?
    Jarrett, Kevin
    Kavukcuoglu, Koray
    Ranzato, Marc'Aurelio
    LeCun, Yann
    [J]. 2009 IEEE 12TH INTERNATIONAL CONFERENCE ON COMPUTER VISION (ICCV), 2009, : 2146 - 2153
  • [40] Kairouz P, 2015, PR MACH LEARN RES, V37, P1376