GANobfuscator: Mitigating Information Leakage Under GAN via Differential Privacy

被引:126
|
作者
Xu, Chugui [1 ]
Ren, Ju [1 ]
Zhang, Deyu [1 ]
Zhang, Yaoxue [1 ]
Qin, Zhan [2 ]
Ren, Kui [2 ]
机构
[1] Cent South Univ, Sch Comp Sci & Engn, Changsha 410083, Hunan, Peoples R China
[2] Zhejiang Univ, Inst Cyberspace Res, Hangzhou 310058, Zhejiang, Peoples R China
基金
美国国家科学基金会;
关键词
Information leakage; generative adversarial network; deep learning; differential privacy; NOISE;
D O I
10.1109/TIFS.2019.2897874
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
By learning generative models of semantic-rich data distributions from samples, generative adversarial network (GAN) has recently attracted intensive research interests due to its excellent empirical performance as a generative model. The model is used to estimate the underlying distribution of a dataset and randomly generate realistic samples according to their estimated distribution. However, GANs can easily remember training samples due to the high model complexity of deep networks. When GANs are applied to private or sensitive data, the concentration of distribution may divulge some critical information. It consequently requires new technological advances to mitigate the information leakage under GANs. To address this issue, we propose GANobfuscator, a differentially private GAN, which can achieve differential privacy under GANs by adding carefully designed noise to gradients during the learning procedure. With GANobfuscator, analysts are able to generate an unlimited amount of synthetic data for arbitrary analysis tasks without disclosing the privacy of training data. Moreover, we theoretically prove that GANobfuscator can provide strict privacy guarantee with differential privacy. In addition, we develop a gradient-pruning strategy for GANobfuscator to improve the scalability and stability of data training. Through extensive experimental evaluation on benchmark datasets, we demonstrate that GANobfuscator can produce high-quality generated data and retain desirable utility under practical privacy budgets.
引用
收藏
页码:2358 / 2371
页数:14
相关论文
共 50 条
  • [1] WDP-GAN: Weighted Graph Generation With GAN Under Differential Privacy
    Hou, Lihe
    Ni, Weiwei
    Zhang, Sen
    Fu, Nan
    Zhang, Dongyue
    IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2023, 20 (04): : 5155 - 5165
  • [2] Quantifying Membership Privacy via Information Leakage
    Saeidian, Sara
    Cervia, Giulia
    Oechtering, Tobias J.
    Skoglund, Mikael
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 : 3096 - 3108
  • [3] Botnet detection and information leakage mitigation with differential privacy under generative adversarial networks
    Feizi, Sanaz
    Ghaffari, Hamidreza
    CLUSTER COMPUTING-THE JOURNAL OF NETWORKS SOFTWARE TOOLS AND APPLICATIONS, 2025, 28 (02):
  • [4] Unexpected Information Leakage of Differential Privacy Due to the Linear Property of Queries
    Huang, Wen
    Zhou, Shijie
    Liao, Yongjian
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2021, 16 (16) : 3123 - 3137
  • [5] Mitigating Privacy Leakage in Anomalous Building Data Streams
    Almashor, Mahathir
    Fadiansyah, Akbar
    Pathmabandu, Chehara
    Amos, Matt
    Chamikara, M. A. P.
    PROCEEDINGS OF THE 10TH ACM INTERNATIONAL CONFERENCE ON SYSTEMS FOR ENERGY-EFFICIENT BUILDINGS, CITIES, AND TRANSPORTATION, BUILDSYS 2023, 2023, : 333 - 339
  • [6] A Graph Symmetrization Bound on Channel Information Leakage Under Blowfish Privacy
    Edwards, Tobias
    Rubinstein, Benjamin I. P.
    Zhang, Zuhe
    Zhou, Sanming
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2022, 68 (01) : 538 - 548
  • [7] Privacy Leakage in GAN Enabled Load Profile Synthesis
    Huang, Jiaqi
    Wu, Chenye
    2022 IEEE SUSTAINABLE POWER AND ENERGY CONFERENCE (ISPEC), 2022,
  • [8] Measures of Information Leakage for Incomplete Statistical Information: Application to a Binary Privacy Mechanism
    Sakib, Shahnewaz Karim
    Amariucai, George T.
    Guan, Yong
    ACM TRANSACTIONS ON PRIVACY AND SECURITY, 2023, 26 (04)
  • [9] Deep Models Under the GAN: Information Leakage from Collaborative Deep Learning
    Hitaj, Briland
    Ateniese, Giuseppe
    Perez-Cruz, Fernando
    CCS'17: PROCEEDINGS OF THE 2017 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2017, : 603 - 618
  • [10] Granular data representation under privacy protection: Tradeoff between data utility and privacy via information granularity
    Zhang, Ge
    Zhu, Xiubin
    Yin, Li
    Pedrycz, Witold
    Li, Zhiwu
    APPLIED SOFT COMPUTING, 2022, 131