Pith. sign in

REVIEW 1 cited by

Directional Privacy for Deep Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2211.04686 v3 pith:HWVO3YJK submitted 2022-11-09 cs.LG cs.CR

classification cs.LGcs.CR
keywords privacydeepepsilongaussiangradientslearningmechanismtraining
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

Differentially Private Stochastic Gradient Descent (DP-SGD) is a key method for applying privacy in the training of deep learning models. It applies isotropic Gaussian noise to gradients during training, which can perturb these gradients in any direction, damaging utility. Metric DP, however, can provide alternative mechanisms based on arbitrary metrics that might be more suitable for preserving utility. In this paper, we apply \textit{directional privacy}, via a mechanism based on the von Mises-Fisher (VMF) distribution, to perturb gradients in terms of \textit{angular distance} so that gradient direction is broadly preserved. We show that this provides both $\epsilon$-DP and $\epsilon d$-privacy for deep learning training, rather than the $(\epsilon, \delta)$-privacy of the Gaussian mechanism. Experiments on key datasets then indicate that the VMF mechanism can outperform the Gaussian in the utility-privacy trade-off. In particular, our experiments provide a direct empirical comparison of privacy between the two approaches in terms of their ability to defend against reconstruction and membership inference.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. What is the Cost of Differential Privacy for Deep Learning-Based Trajectory Generation?

    cs.CR 2025-06 reject novelty 6.0 of 10

    DP-SGD causes large utility loss in deep trajectory generation, a new DP mechanism for conditional inputs helps stabilize GANs, and GANs overtake diffusion models when formal privacy is required.

Pith tools