Pith. sign in

REVIEW 2 cited by

Differentially Private Model Publishing for Deep Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1904.02200 v5 pith:HTUIR4YU submitted 2019-04-03 cs.CR cs.LG

classification cs.CRcs.LG
keywords privacymodeltrainingapproachlossprivateaccuracybudget
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Deep learning techniques based on neural networks have shown significant success in a wide range of AI tasks. Large-scale training datasets are one of the critical factors for their success. However, when the training datasets are crowdsourced from individuals and contain sensitive information, the model parameters may encode private information and bear the risks of privacy leakage. The recent growing trend of the sharing and publishing of pre-trained models further aggravates such privacy risks. To tackle this problem, we propose a differentially private approach for training neural networks. Our approach includes several new techniques for optimizing both privacy loss and model accuracy. We employ a generalization of differential privacy called concentrated differential privacy(CDP), with both a formal and refined privacy loss analysis on two different data batching methods. We implement a dynamic privacy budget allocator over the course of training to improve model accuracy. Extensive experiments demonstrate that our approach effectively improves privacy loss accounting, training efficiency and model quality under a given privacy budget.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Privacy-Preserving Tensor Factorization for Collaborative Health Data Analysis

    cs.LG 2019-08 reject novelty 6.0 of 10

    DPFact combines elastic averaging SGD, output perturbation under zero-concentrated differential privacy, and l2,1 regularization to enable collaborative tensor factorization for phenotyping from distributed EHRs.

  2. AdaCliP: Adaptive Clipping for Private SGD

    cs.LG 2019-08 conditional novelty 6.0 of 10

    Coordinate-wise adaptive clipping in DP-SGD, with per-coordinate scales derived from a noise-minimization problem, yields higher MNIST accuracy than standard L2 clipping at the same privacy budget.

Pith tools