REVIEW 2 cited by
Privacy in Deep Learning: A Survey
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
The ever-growing advances of deep learning in many areas including vision, recommendation systems, natural language processing, etc., have led to the adoption of Deep Neural Networks (DNNs) in production systems. The availability of large datasets and high computational power are the main contributors to these advances. The datasets are usually crowdsourced and may contain sensitive information. This poses serious privacy concerns as this data can be misused or leaked through various vulnerabilities. Even if the cloud provider and the communication link is trusted, there are still threats of inference attacks where an attacker could speculate properties of the data used for training, or find the underlying model architecture and parameters. In this survey, we review the privacy concerns brought by deep learning, and the mitigating techniques introduced to tackle these issues. We also show that there is a gap in the literature regarding test-time inference privacy, and propose possible future research directions.
Forward citations
Cited by 2 Pith papers
-
Steps Adaptive Decay DPSGD: Enhancing Performance on Imbalanced Datasets with Differential Privacy with HAM10000
SAD-DPSGD, a step-adaptive decay schedule for noise and clipping in DP-SGD, reports about 1% higher accuracy than Auto-DPSGD on HAM10000 under differential privacy.
-
Cellular Traffic Prediction via Byzantine-robust Asynchronous Federated Learning
The paper proposes BAFDP, an asynchronous Byzantine-robust federated learning algorithm with local differential privacy, and reports superior traffic prediction accuracy over eight baselines on three datasets.
Discussion (0). Continue with ORCID to comment.