GANobfuscator: Mitigating Information Leakage Under GAN via Differential Privacy

被引:126
|
作者
Xu, Chugui [1 ]
Ren, Ju [1 ]
Zhang, Deyu [1 ]
Zhang, Yaoxue [1 ]
Qin, Zhan [2 ]
Ren, Kui [2 ]
机构
[1] Cent South Univ, Sch Comp Sci & Engn, Changsha 410083, Hunan, Peoples R China
[2] Zhejiang Univ, Inst Cyberspace Res, Hangzhou 310058, Zhejiang, Peoples R China
基金
美国国家科学基金会;
关键词
Information leakage; generative adversarial network; deep learning; differential privacy; NOISE;
D O I
10.1109/TIFS.2019.2897874
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
By learning generative models of semantic-rich data distributions from samples, generative adversarial network (GAN) has recently attracted intensive research interests due to its excellent empirical performance as a generative model. The model is used to estimate the underlying distribution of a dataset and randomly generate realistic samples according to their estimated distribution. However, GANs can easily remember training samples due to the high model complexity of deep networks. When GANs are applied to private or sensitive data, the concentration of distribution may divulge some critical information. It consequently requires new technological advances to mitigate the information leakage under GANs. To address this issue, we propose GANobfuscator, a differentially private GAN, which can achieve differential privacy under GANs by adding carefully designed noise to gradients during the learning procedure. With GANobfuscator, analysts are able to generate an unlimited amount of synthetic data for arbitrary analysis tasks without disclosing the privacy of training data. Moreover, we theoretically prove that GANobfuscator can provide strict privacy guarantee with differential privacy. In addition, we develop a gradient-pruning strategy for GANobfuscator to improve the scalability and stability of data training. Through extensive experimental evaluation on benchmark datasets, we demonstrate that GANobfuscator can produce high-quality generated data and retain desirable utility under practical privacy budgets.
引用
收藏
页码:2358 / 2371
页数:14
相关论文
共 50 条
  • [31] Differential Privacy under Incalculable Sensitivity
    Mimoto, Tomoaki
    Hashimoto, Masayuki
    Yokoyama, Hiroyuki
    Nakamura, Toru
    Isohara, Takamasa
    Kojima, Ryosuke
    Hasegawa, Aki
    Okuno, Yasushi
    2022 6TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY, CSP 2022, 2022, : 27 - 31
  • [32] Preserving differential privacy under finite-precision semantics
    Gazeau, Ivan
    Miller, Dale
    Palamidessi, Catuscia
    THEORETICAL COMPUTER SCIENCE, 2016, 655 : 92 - 108
  • [33] CASCADING BANDIT UNDER DIFFERENTIAL PRIVACY
    Wang, Kun
    Dong, Jing
    Wang, Baoxiang
    Li, Shuai
    2022 IEEE INTERNATIONAL CONFERENCE ON ACOUSTICS, SPEECH AND SIGNAL PROCESSING (ICASSP), 2022, : 4418 - 4422
  • [34] Information-Theoretic Approaches to Differential Privacy
    Unsal, Ayse
    Onen, Melek
    ACM COMPUTING SURVEYS, 2024, 56 (03)
  • [35] On the Relation Between Identifiability, Differential Privacy, and Mutual-Information Privacy
    Wang, Weina
    Ying, Lei
    Zhang, Junshan
    IEEE TRANSACTIONS ON INFORMATION THEORY, 2016, 62 (09) : 5018 - 5029
  • [36] Explaining ε in local differential privacy through the lens of quantitative information flow
    Fernandes, Natasha
    McIver, Annabelle
    Sadeghi, Parastoo
    2024 IEEE 37TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, CSF 2024, 2024, : 419 - 432
  • [37] Variations and Extensions of Information Leakage Metrics with Applications to Privacy Problems with Imperfect Statistical Information
    Sakib, Shahnewaz Karim
    Amariucai, George T.
    Guan, Yong
    2023 IEEE 36TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM, CSF, 2023, : 407 - 422
  • [38] SENSITIVITY-INDEPENDENT DIFFERENTIAL PRIVACY VIA PRIOR KNOWLEDGE REFINEMENT
    Soria-Comas, Jordi
    Domingo-Ferrer, Josep
    INTERNATIONAL JOURNAL OF UNCERTAINTY FUZZINESS AND KNOWLEDGE-BASED SYSTEMS, 2012, 20 (06) : 855 - 876
  • [39] Privacy-preserving face attribute classification via differential privacy
    Zhang, Xiaoting
    Wang, Tao
    Ji, Junhao
    Zhang, Yushu
    Lan, Rushi
    NEUROCOMPUTING, 2025, 626
  • [40] Distributed Differential Privacy via Shuffling Versus Aggregation: A Curious Study
    Wei, Yu
    Jia, Jingyu
    Wu, Yuduo
    Hu, Changhui
    Dong, Changyu
    Liu, Zheli
    Chen, Xiaofeng
    Peng, Yun
    Wang, Shaowei
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 2501 - 2516