Citadel++ claims to protect dataset, model, and code confidentiality, user-level differential privacy, and execution integrity in collaborative training using VM-level trusted execution environments and enhanced DP-SGD.
Differentially private training of residual networks with scale normalisation
1 Pith paper cite this work. Polarity classification is still indexing.
abstract
The training of neural networks with Differentially Private Stochastic Gradient Descent offers formal Differential Privacy guarantees but introduces accuracy trade-offs. In this work, we propose to alleviate these trade-offs in residual networks with Group Normalisation through a simple architectural modification termed ScaleNorm by which an additional normalisation layer is introduced after the residual block's addition operation. Our method allows us to further improve on the recently reported state-of-the art on CIFAR-10, achieving a top-1 accuracy of 82.5% ({\epsilon}=8.0) when trained from scratch.
citation-role summary
citation-polarity summary
fields
cs.DC 1years
2024 1verdicts
REJECT 1roles
background 1polarities
background 1representative citing papers
citing papers explorer
-
Protecting Confidentiality, Privacy and Integrity in Collaborative Learning
Citadel++ claims to protect dataset, model, and code confidentiality, user-level differential privacy, and execution integrity in collaborative training using VM-level trusted execution environments and enhanced DP-SGD.