AIセキュリティポータル K Program
Have it your way: Individualized Privacy Assignment for DP-SGD
Share
Abstract
When training a machine learning model with differential privacy, one sets a privacy budget. This budget represents a maximal privacy violation that any user is willing to face by contributing their data to the training set. We argue that this approach is limited because different users may have different privacy expectations. Thus, setting a uniform privacy budget across all points may be overly conservative for some users or, conversely, not sufficiently protective for others. In this paper, we capture these preferences through individualized privacy budgets. To demonstrate their practicality, we introduce a variant of Differentially Private Stochastic Gradient Descent (DP-SGD) which supports such individualized budgets. DP-SGD is the canonical approach to training models with differential privacy. We modify its data sampling and gradient noising mechanisms to arrive at our approach, which we call Individualized DP-SGD (IDP-SGD). Because IDP-SGD provides privacy guarantees tailored to the preferences of individual users and their data points, we find it empirically improves privacy-utility trade-offs.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, Li Zhang
Published: 2016
Hypothesis testing interpretations and renyi differential privacy
Borja Balle, Gilles Barthe, Marco Gaboardi, Justin Hsu, Tetsuya Sato
Published: 2020
Bounds on the sample complexity for private learning and private data release
Amos Beimel, Shiva Prasad Kasiviswanathan, Kobbi Nissim
Published: 2010
Privacy in e-commerce: Stated preferences vs. actual behavior
Bettina Berendt, Oliver Günther, Sarah Spiekermann
Published: 2005
A large annotated corpus for learning natural language inference
Bowman, S. R., Angeli, G., Potts, C., Manning, C. D.
Published: 2015
Membership inference attacks from first principles
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, Florian Tramer
Published: 2022
An investigation into user expectations for differential privacy
Rachel Cummings, Gabriel Kaptchuk, Elissa M Redmiles
Published: 2021
Differential privacy: A survey of results
C. Dwork
Published: 2008
Individual privacy accounting via a renyi filter
Vitaly Feldman, Tijana Zrnic
Published: 2021
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, Thomas Ristenpart
Published: 2015
Property testing for differential privacy
Anna C Gilbert, Audra McMillan
Published: 2018
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, Jian Sun
Published: 2016
Privacy practices of internet users: Self-reports versus observed behavior
Carlos Jensen, Colin Potts, Christian Jensen
Published: 2005
Differentially private bagging: Improved utility and cheaper privacy than subsample-and-aggregate
James Jordon, Jinsung Yoon, Mihaela van der Schaar
Published: 2019
Conservative or liberal? personalized differential privacy
Zach Jorgensen, Ting Yu, Graham Cormode
Published: 2015
Practical and private (deep) learning without sampling or shuffling
Peter Kairouz, Brendan McMahan, Shuang Song, Om Thakkar, Abhradeep Thakurta, Zheng Xu
Published: 2021
Bert: Pre-training of deep bidirectional transformers for language understanding
Jacob Devlin, Ming-Wei Chang, Kenton Lee, Kristina Toutanova
Published: 2019
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton
Published: 2009
Partitioning-based mechanisms under personalized differential privacy
Haoran Li, Li Xiong, Zhanglong Ji, Xiaoqian Jiang
Published: 2017
Communication-Efficient Learning of Deep Networks from Decentralized Data
H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, Blaise Agüera y Arcas
Published: 2.18.2016
Rényi differential privacy
Ilya Mironov
Published: 2017
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, Andrew Y Ng
Published: 2011
Utility-aware exponential mechanism for personalized differential privacy
Ben Niu, Yahong Chen, Boyang Wang, Jin Cao, Fenghua Li
Published: 2020
Adapdp: Adaptive personalized differential privacy
Ben Niu, Yahong Chen, Boyang Wang, Zhibo Wang, Fenghua Li, Jin Cao
Published: 2021
Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data
Nicolas Papernot, Martín Abadi, Úlfar Erlingsson, Ian Goodfellow, Kunal Talwar
Published: 10.19.2016
Scalable private learning with pate
Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, Ulfar Erlingsson
Published: 2018
Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning
Ahmed Salem, Apratim Bhattacharya, Michael Backes, Mario Fritz, Yang Zhang
Published: 4.2.2019
Enhanced Membership Inference Attacks against Machine Learning Models
Jiayuan Ye, Aadyaa Maddi, Sasi Kumar Murakonda, Vincent Bindschaedler, Reza Shokri
Published: 11.18.2021
Privacy needs reflection: Conceptional design rationales for privacy-preserving explanation user interfaces
Peter Sörries, Claudia Müller-Birn, Katrin Glinka, Franziska Boenisch, Marian Margraf, Sabine Sayegh-Jodehl, Matthias Rose
Published: 2021
ldp-fed: Federated learning with local differential privacy
Stacey Truex, Ling Liu, Ka-Ho Chow, Mehmet Emre Gursoy, Wenqi Wei
Published: 2020
Towards effective differential privacy communication for users’ data sharing decision and comprehension
Aiping Xiong, Tianhao Wang, Ninghui Li, Somesh Jha
Published: 2020
Differentially private learning needs hidden state (or much faster convergence)
Jiayuan Ye, Reza Shokri
Published: 2022
Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, Somesh Jha
Published: 9.6.2017
The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks
Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, Dawn Song
Published: 11.17.2019
Share