DP-SGD vs PATE: Which Has Less Disparate Impact on Model Accuracy?
read the original abstract
Recent advances in differentially private deep learning have demonstrated that application of differential privacy, specifically the DP-SGD algorithm, has a disparate impact on different sub-groups in the population, which leads to a significantly high drop-in model utility for sub-populations that are under-represented (minorities), compared to well-represented ones. In this work, we aim to compare PATE, another mechanism for training deep learning models using differential privacy, with DP-SGD in terms of fairness. We show that PATE does have a disparate impact too, however, it is much less severe than DP-SGD. We draw insights from this observation on what might be promising directions in achieving better fairness-privacy trade-offs.
This paper has not been read by Pith yet.
Forward citations
Cited by 2 Pith papers
-
Tradeoffs in Privacy, Welfare, and Fairness for Facility Location
Privacy and fairness cannot both be guaranteed in facility location over all datasets, but mechanisms exist that are optimal or near-optimal on welfare and fairness for natural data while preserving worst-case differe...
-
INO-SGD: Addressing Utility Imbalance under Individualized Differential Privacy
INO-SGD down-weights data in each batch to improve model performance on strongly private data while satisfying individualized differential privacy constraints.
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.