Privacy-Preserving Student Learning with Differentially Private Data-Free Distillation

被引:2
|
作者
Liu, Bochao [1 ,2 ]
Lu, Jianghu [1 ,2 ]
Wang, Pengju [1 ,2 ]
Zhang, Junjie [3 ]
Zeng, Dan [3 ]
Qian, Zhenxing [4 ]
Ge, Shiming [1 ,2 ]
机构
[1] Chinese Acad Sci, Inst Informat Engn, Beijing 100095, Peoples R China
[2] Univ Chinese Acad Sci, Sch Cyber Secur, Beijing 100049, Peoples R China
[3] Shanghai Univ, Sch Commun & Informat Engn, Shanghai 200444, Peoples R China
[4] Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
来源
2022 IEEE 24TH INTERNATIONAL WORKSHOP ON MULTIMEDIA SIGNAL PROCESSING (MMSP) | 2022年
基金
北京市自然科学基金;
关键词
differential privacy; teacher-student learning; knowledge distillation;
D O I
10.1109/MMSP55362.2022.9950001
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Deep learning models can achieve high inference accuracy by extracting rich knowledge from massive well-annotated data, but may pose the risk of data privacy leakage in practical deployment. In this paper, we present an effective teacher-student learning approach to train privacy-preserving deep learning models via differentially private data-free distillation. The main idea is generating synthetic data to learn a student that can mimic the ability of a teacher well-trained on private data. In the approach, a generator is first pretrained in a data-free manner by incorporating the teacher as a fixed discriminator. With the generator, massive synthetic data can be generated for model training without exposing data privacy. Then, the synthetic data is fed into the teacher to generate private labels. Towards this end, we propose a label differential privacy algorithm termed selective randomized response to protect the label information. Finally, a student is trained on the synthetic data with the supervision of private labels. In this way, both data privacy and label privacy are well protected in a unified framework, leading to privacy-preserving models. Extensive experiments and analysis clearly demonstrate the effectiveness of our approach.
引用
收藏
页数:6
相关论文
共 50 条
  • [21] Differentially Privacy-Preserving Federated Learning Using Wasserstein Generative Adversarial Network
    Wan, Yichen
    Qu, Youyang
    Gao, Longxiang
    Xiang, Yong
    26TH IEEE SYMPOSIUM ON COMPUTERS AND COMMUNICATIONS (IEEE ISCC 2021), 2021,
  • [22] Data-Free Ensemble Knowledge Distillation for Privacy-conscious Multimedia Model Compression
    Hao, Zhiwei
    Luo, Yong
    Hu, Han
    An, Jianping
    Wen, Yonggang
    PROCEEDINGS OF THE 29TH ACM INTERNATIONAL CONFERENCE ON MULTIMEDIA, MM 2021, 2021, : 1803 - 1811
  • [23] Anonymous and Privacy-Preserving Federated Learning With Industrial Big Data
    Zhao, Bin
    Fan, Kai
    Yang, Kan
    Wang, Zilong
    Li, Hui
    Yang, Yintang
    IEEE TRANSACTIONS ON INDUSTRIAL INFORMATICS, 2021, 17 (09) : 6314 - 6323
  • [24] Adaptive privacy-preserving federated learning
    Liu, Xiaoyuan
    Li, Hongwei
    Xu, Guowen
    Lu, Rongxing
    He, Miao
    PEER-TO-PEER NETWORKING AND APPLICATIONS, 2020, 13 (06) : 2356 - 2366
  • [25] Privacy-Preserving Machine Learning [Cryptography]
    Kerschbaum, Florian
    Lukas, Nils
    IEEE SECURITY & PRIVACY, 2023, 21 (06) : 90 - 94
  • [26] Survey on Privacy-Preserving Machine Learning
    Liu J.
    Meng X.
    Jisuanji Yanjiu yu Fazhan/Computer Research and Development, 2020, 57 (02): : 346 - 362
  • [27] Privacy-Preserving Stochastic Gradual Learning
    Han, Bo
    Tsang, Ivor W.
    Xiao, Xiaokui
    Chen, Ling
    Fung, Sai-Fu
    Yu, Celina P.
    IEEE TRANSACTIONS ON KNOWLEDGE AND DATA ENGINEERING, 2021, 33 (08) : 3129 - 3140
  • [28] Privacy-Preserving Sequential Data Publishing
    Wang, Huili
    Ma, Wenping
    Zheng, Haibin
    Liang, Zhi
    Wu, Qianhong
    NETWORK AND SYSTEM SECURITY, NSS 2019, 2019, 11928 : 596 - 614
  • [29] Adaptive privacy-preserving federated learning
    Xiaoyuan Liu
    Hongwei Li
    Guowen Xu
    Rongxing Lu
    Miao He
    Peer-to-Peer Networking and Applications, 2020, 13 : 2356 - 2366
  • [30] Privacy-preserving Techniques in Federated Learning
    Liu Y.-X.
    Chen H.
    Liu Y.-H.
    Li C.-P.
    Ruan Jian Xue Bao/Journal of Software, 2022, 33 (03): : 1057 - 1092