A Survey on Differentially Private Machine Learning [Review Article]

被引:77
作者
Gong, Maoguo [1 ]
Xie, Yu [1 ]
Pan, Ke [1 ]
Feng, Kaiyuan [1 ]
Qin, A. K. [2 ]
机构
[1] Xidian Univ, Sch Elect Engn, Xian, Peoples R China
[2] Swinburne Univ Technol, Dept Comp Sci & Software Engn, Melbourne, Vic, Australia
关键词
CLASSIFICATION;
D O I
10.1109/MCI.2020.2976185
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Recent years have witnessed remarkable successes of machine learning in various applications. However, machine learning models suffer from a potential risk of leaking private information contained in training data, which have attracted increasing research attention. As one of the mainstream privacy- preserving techniques, differential privacy provides a promising way to prevent the leaking of individual-level privacy in training data while preserving the quality of training data for model building. This work provides a comprehensive survey on the existing works that incorporate differential privacy with machine learning, so- called differentially private machine learning and categorizes them into two broad categories as per different differential privacy mechanisms: the Laplace/ Gaussian/exponential mechanism and the output/objective perturbation mechanism. In the former, a calibrated amount of noise is added to the non-private model and in the latter, the output or the objective function is perturbed by random noise. Particularly, the survey covers the techniques of differentially private deep learning to alleviate the recent concerns about the privacy of big data contributors. In addition, the research challenges in terms of model utility, privacy level and applications are discussed. To tackle these challenges, several potential future research directions for differentially private machine learning are pointed out. © 2020 IEEE.
引用
收藏
页码:49 / 88
页数:17
相关论文
共 128 条
[1]   Deep Learning with Differential Privacy [J].
Abadi, Martin ;
Chu, Andy ;
Goodfellow, Ian ;
McMahan, H. Brendan ;
Mironov, Ilya ;
Talwar, Kunal ;
Zhang, Li .
CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, :308-318
[2]   Differentially Private Mixture of Generative Neural Networks [J].
Acs, Gergely ;
Melis, Luca ;
Castelluccia, Claude ;
De Cristofaro, Emiliano .
2017 17TH IEEE INTERNATIONAL CONFERENCE ON DATA MINING (ICDM), 2017, :715-720
[3]  
Agarwal N, 2017, PR MACH LEARN RES, V70
[4]  
Angluin D., 1992, Proceedings of the Twenty-Fourth Annual ACM Symposium on the Theory of Computing, P351, DOI 10.1145/129712.129746
[5]  
[Anonymous], 2017, PRIVACY PRESERVING G
[6]  
[Anonymous], 2010, Commun. Surveys Tuts., DOI DOI 10.1038/nature14539
[7]  
[Anonymous], 2009, P ANN INT C MACH LEA, DOI DOI 10.1145/1553374.1553453
[8]  
[Anonymous], 2002, P ADV NEURAL INF PRO
[9]  
[Anonymous], 2005, P 31 INT C VER LARG, DOI DOI 10.5555/1083592.1083696
[10]  
[Anonymous], 2014, 27THINT C NEURAL INF