Deep Domain Adaptation With Differential Privacy

被引:23
|
作者
Wang, Qian [1 ,2 ]
Li, Zixi [1 ,2 ]
Zou, Qin [3 ]
Zhao, Lingchen [1 ,2 ]
Wang, Song [4 ,5 ]
机构
[1] Wuhan Univ, Key Lab Aerosp Informat Secur & Trusted Comp, Minist Educ, Sch Cyber Sci & Engn, Wuhan 430072, Peoples R China
[2] State Key Lab Cryptog, Beijing 100878, Peoples R China
[3] Wuhan Univ, Sch Comp Sci, Wuhan 430072, Peoples R China
[4] Univ South Carolina, Dept Comp Sci & Engn, Columbia, SC 29201 USA
[5] Tianjin Univ, Coll Intelligence & Comp, Tianjin 300072, Peoples R China
关键词
Domain adaptation; privacy preservation; differential privacy; deep learning; convolutional neural network; KERNEL; NOISE;
D O I
10.1109/TIFS.2020.2983254
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Nowadays, it usually requires a massive amount of labeled data to train a deep neural network. When no labeled data is available in some application scenarios, domain adaption can be employed to transfer a learner from one or more source domains with labeled data to a target domain with unlabeled data. However, due to the exposure of the trained model to the target domain, the user privacy may potentially be compromised. Nevertheless, the private information may be encoded into the representations in different stages of the deep neural networks, i.e., hierarchical convolutional feature maps, which poses a great challenge for a full-fledged privacy protection. In this paper, we propose a novel differentially private domain adaptation framework called DPDA to achieve domain adaptation with privacy assurance. Specifically, we perform domain adaptation in an adversarial-learning manner and embed the differentially private design into specific layers and learning processes. Although applying differential privacy techniques directly will undermine the performance of deep neural networks, DPDA can increase the classification accuracy for the unlabeled target data compared to the prior arts. We conduct extensive experiments on standard benchmark datasets, and the results show that our proposed DPDA can indeed achieve high accuracy in many domain adaptation tasks with only a modest privacy loss.
引用
收藏
页码:3093 / 3106
页数:14
相关论文
共 50 条
  • [21] Deep Domain Adaptation for Pavement Crack Detection
    Liu, Huijun
    Yang, Chunhua
    Li, Ao
    Huang, Sheng
    Feng, Xin
    Ruan, Zhimin
    Ge, Yongxin
    IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (02) : 1669 - 1681
  • [22] Can Stochastic Gradient Langevin Dynamics Provide Differential Privacy for Deep Learning?
    Heller, Guy
    Fetaya, Ethan
    2023 IEEE CONFERENCE ON SECURE AND TRUSTWORTHY MACHINE LEARNING, SATML, 2023, : 68 - 106
  • [23] Beyond Sharing Weights for Deep Domain Adaptation
    Rozantsev, Artem
    Salzmann, Mathieu
    Fua, Pascal
    IEEE TRANSACTIONS ON PATTERN ANALYSIS AND MACHINE INTELLIGENCE, 2019, 41 (04) : 801 - 814
  • [24] Preserving differential privacy in convolutional deep belief networks
    NhatHai Phan
    Xintao Wu
    Dejing Dou
    Machine Learning, 2017, 106 : 1681 - 1704
  • [25] Adaptive Clipping Bound of Deep Learning with Differential Privacy
    Hu, Yuhang
    Li, De
    Tan, Zhou
    Li, Xianxian
    Wang, Jinyan
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 428 - 435
  • [26] Preserving differential privacy in convolutional deep belief networks
    NhatHai Phan
    Wu, Xintao
    Dou, Dejing
    MACHINE LEARNING, 2017, 106 (9-10) : 1681 - 1704
  • [27] Privacy-Preserving Localization for Underwater Acoustic Sensor Networks: A Differential Privacy-Based Deep Learning Approach
    Yan, Jing
    Zheng, Yuhan
    Yang, Xian
    Chen, Cailian
    Guan, Xinping
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2025, 20 : 737 - 752
  • [28] Towards Privacy-Preserving Domain Adaptation
    Kim, Youngeun
    Cho, Donghyeon
    Hong, Sungeun
    IEEE SIGNAL PROCESSING LETTERS, 2020, 27 : 1675 - 1679
  • [29] DEEP CLUSTERING FOR DOMAIN ADAPTATION
    Gao, Boyan
    Yang, Yongxin
    Gouk, Henry
    Hospedales, Timothy M.
    2020 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH, AND SIGNAL PROCESSING, 2020, : 4247 - 4251
  • [30] Deep Discriminative Domain Adaptation
    Zhang, Changchun
    Zhao, Qingjie
    INFORMATION SCIENCES, 2021, 575 : 599 - 610