Deep Learning with Label Differential Privacy

被引:0
作者
Ghazi, Badih [1 ]
Golowich, Noah [2 ]
Kumar, Ravi [1 ]
Manurangsi, Pasin [1 ]
Zhang, Chiyuan [1 ]
机构
[1] Google Res, San Francisco, CA 94105 USA
[2] MIT, EECS, Cambridge, MA 02139 USA
来源
ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS 34 (NEURIPS 2021) | 2021年 / 34卷
关键词
NOISE;
D O I
暂无
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The Randomized Response (RR) algorithm [96] is a classical technique to improve robustness in survey aggregation, and has been widely adopted in applications with differential privacy guarantees. We propose a novel algorithm, Randomized Response with Prior (RRWithPrior), which can provide more accurate results while maintaining the same level of privacy guaranteed by RR. We then apply RRWithPrior to learn neural networks with label differential privacy (Labe DP), and show that when only the label needs to be protected, the model performance can be significantly improved over the previous state-of-the-art private baselines. Moreover, we study different ways to obtain priors, which when used with RRWithPrior can additionally improve the model performance, further reducing the accuracy gap between private and non-private models. We complement the empirical results with theoretical analysis showing that Labe DP is provably easier than protecting both the inputs and labels.
引用
收藏
页数:15
相关论文
共 105 条
  • [1] Abadi M, 2016, PROCEEDINGS OF OSDI'16: 12TH USENIX SYMPOSIUM ON OPERATING SYSTEMS DESIGN AND IMPLEMENTATION, P265
  • [2] Deep Learning with Differential Privacy
    Abadi, Martin
    Chu, Andy
    Goodfellow, Ian
    McMahan, H. Brendan
    Mironov, Ilya
    Talwar, Kunal
    Zhang, Li
    [J]. CCS'16: PROCEEDINGS OF THE 2016 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2016, : 308 - 318
  • [3] The US Census Bureau Adopts Differential Privacy
    Abowd, John M.
    [J]. KDD'18: PROCEEDINGS OF THE 24TH ACM SIGKDD INTERNATIONAL CONFERENCE ON KNOWLEDGE DISCOVERY & DATA MINING, 2018, : 2867 - 2867
  • [4] Agarwal A, 2009, IMMUNE INFERTILITY, P155, DOI 10.1007/978-3-642-01379-9_3.2
  • [5] Agarwal A., 2019, ARXIV190304243
  • [6] Private PAC Learning Implies Finite Littlestone Dimension
    Alon, Noga
    Livni, Roi
    Malliaris, Maryanthe
    Moran, Shay
    [J]. PROCEEDINGS OF THE 51ST ANNUAL ACM SIGACT SYMPOSIUM ON THEORY OF COMPUTING (STOC '19), 2019, : 852 - 860
  • [7] Anderson E., 2021, MASKED LEARNING AGGR
  • [8] Anderson E., 2021, MASKED LEARNING AGGR
  • [9] [Anonymous], 2011, JMLR, DOI DOI 10.1186/1471-2164-12-192
  • [10] [Anonymous], 2012, J MACH LEARN RES