Private Prediction Sets

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Angelopoulos, Anastasios N., Bates, Stephen, Zrnic, Tijana, Jordan, Michael I.
Format: Preprint
Veröffentlicht: 2021
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866914698495000576
author Angelopoulos, Anastasios N.
Bates, Stephen
Zrnic, Tijana
Jordan, Michael I.
author_facet Angelopoulos, Anastasios N.
Bates, Stephen
Zrnic, Tijana
Jordan, Michael I.
contents In real-world settings involving consequential decision-making, the deployment of machine learning systems generally requires both reliable uncertainty quantification and protection of individuals' privacy. We present a framework that treats these two desiderata jointly. Our framework is based on conformal prediction, a methodology that augments predictive models to return prediction sets that provide uncertainty quantification -- they provably cover the true response with a user-specified probability, such as 90%. One might hope that when used with privately-trained models, conformal prediction would yield privacy guarantees for the resulting prediction sets; unfortunately, this is not the case. To remedy this key problem, we develop a method that takes any pre-trained predictive model and outputs differentially private prediction sets. Our method follows the general approach of split conformal prediction; we use holdout data to calibrate the size of the prediction sets but preserve privacy by using a privatized quantile subroutine. This subroutine compensates for the noise introduced to preserve privacy in order to guarantee correct coverage. We evaluate the method on large-scale computer vision datasets.
format Preprint
id arxiv_https___arxiv_org_abs_2102_06202
institution arXiv
publishDate 2021
record_format arxiv
spellingShingle Private Prediction Sets
Angelopoulos, Anastasios N.
Bates, Stephen
Zrnic, Tijana
Jordan, Michael I.
Machine Learning
Artificial Intelligence
Cryptography and Security
Methodology
In real-world settings involving consequential decision-making, the deployment of machine learning systems generally requires both reliable uncertainty quantification and protection of individuals' privacy. We present a framework that treats these two desiderata jointly. Our framework is based on conformal prediction, a methodology that augments predictive models to return prediction sets that provide uncertainty quantification -- they provably cover the true response with a user-specified probability, such as 90%. One might hope that when used with privately-trained models, conformal prediction would yield privacy guarantees for the resulting prediction sets; unfortunately, this is not the case. To remedy this key problem, we develop a method that takes any pre-trained predictive model and outputs differentially private prediction sets. Our method follows the general approach of split conformal prediction; we use holdout data to calibrate the size of the prediction sets but preserve privacy by using a privatized quantile subroutine. This subroutine compensates for the noise introduced to preserve privacy in order to guarantee correct coverage. We evaluate the method on large-scale computer vision datasets.
title Private Prediction Sets
topic Machine Learning
Artificial Intelligence
Cryptography and Security
Methodology
url https://arxiv.org/abs/2102.06202