GANobfuscator: Mitigating Information Leakage Under GAN via Differential Privacy

被引:126
|
作者
Xu, Chugui [1 ]
Ren, Ju [1 ]
Zhang, Deyu [1 ]
Zhang, Yaoxue [1 ]
Qin, Zhan [2 ]
Ren, Kui [2 ]
机构
[1] Cent South Univ, Sch Comp Sci & Engn, Changsha 410083, Hunan, Peoples R China
[2] Zhejiang Univ, Inst Cyberspace Res, Hangzhou 310058, Zhejiang, Peoples R China
基金
美国国家科学基金会;
关键词
Information leakage; generative adversarial network; deep learning; differential privacy; NOISE;
D O I
10.1109/TIFS.2019.2897874
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
By learning generative models of semantic-rich data distributions from samples, generative adversarial network (GAN) has recently attracted intensive research interests due to its excellent empirical performance as a generative model. The model is used to estimate the underlying distribution of a dataset and randomly generate realistic samples according to their estimated distribution. However, GANs can easily remember training samples due to the high model complexity of deep networks. When GANs are applied to private or sensitive data, the concentration of distribution may divulge some critical information. It consequently requires new technological advances to mitigate the information leakage under GANs. To address this issue, we propose GANobfuscator, a differentially private GAN, which can achieve differential privacy under GANs by adding carefully designed noise to gradients during the learning procedure. With GANobfuscator, analysts are able to generate an unlimited amount of synthetic data for arbitrary analysis tasks without disclosing the privacy of training data. Moreover, we theoretically prove that GANobfuscator can provide strict privacy guarantee with differential privacy. In addition, we develop a gradient-pruning strategy for GANobfuscator to improve the scalability and stability of data training. Through extensive experimental evaluation on benchmark datasets, we demonstrate that GANobfuscator can produce high-quality generated data and retain desirable utility under practical privacy budgets.
引用
收藏
页码:2358 / 2371
页数:14
相关论文
共 50 条
  • [21] Secure Metric Learning via Differential Pairwise Privacy
    Li, Jing
    Pan, Yuangang
    Sui, Yulei
    Tsang, Ivor W.
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 3640 - 3652
  • [22] Privacy Preserving BIRCH Algorithm under Differential Privacy
    Zhang, Yao
    Li, Shuyu
    2017 10TH INTERNATIONAL CONFERENCE ON INTELLIGENT COMPUTATION TECHNOLOGY AND AUTOMATION (ICICTA 2017), 2017, : 48 - 53
  • [23] A Data Leakage Traceability Scheme Based on Differential Privacy and Fingerprint
    Wang, Mingyong
    Zheng, Shuli
    2024 3RD INTERNATIONAL CONFERENCE ON IMAGE PROCESSING AND MEDIA COMPUTING, ICIPMC 2024, 2024, : 327 - 334
  • [24] Distributed Differential Privacy via Shuffling
    Cheu, Albert
    Smith, Adam
    Ullman, Jonathan
    Zeber, David
    Zhilyaev, Maxim
    ADVANCES IN CRYPTOLOGY - EUROCRYPT 2019, PT I, 2019, 11476 : 375 - 403
  • [25] Differential Privacy via Wavelet Transforms
    Xiao, Xiaokui
    Wang, Guozhang
    Gehrke, Johannes
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2011, 23 (08) : 1200 - 1214
  • [26] Mitigating information leakage during critical communication using S*FSM
    Borowczak, Mike
    Vemuri, Ranga
    IET COMPUTERS AND DIGITAL TECHNIQUES, 2019, 13 (04) : 292 - 301
  • [27] Horizontal multi-party data publishing via discriminator regularization and adaptive noise under differential privacy
    Zhang, Pengfei
    Fang, Xiang
    Zhang, Zhikun
    Fang, Xianjin
    Liu, Yining
    Zhang, Ji
    INFORMATION FUSION, 2025, 120
  • [28] Differential Privacy under Continual Observation
    Liang W.-J.
    Chen H.
    Wu Y.-C.
    Zhao D.
    Li C.-P.
    Ruan Jian Xue Bao/Journal of Software, 2020, 31 (06): : 1761 - 1785
  • [29] Detecting Communities under Differential Privacy
    Nguyen, Hiep H.
    Mine, Abdessamad
    Rusinowitch, Michael
    PROCEEDINGS OF THE 2016 ACM WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY (WPES'16), 2016, : 83 - 93
  • [30] RDP-GAN: A Renyi-Differential Privacy Based Generative Adversarial Network
    Ma, Chuan
    Li, Jun
    Ding, Ming
    Liu, Bo
    Wei, Kang
    Weng, Jian
    Poor, H. Vincent
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2023, 20 (06) : 4838 - 4852