Have it your way: Individualized Privacy Assignment for DP-SGD

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Boenisch, Franziska, Mühl, Christopher, Dziedzic, Adam, Rinberg, Roy, Papernot, Nicolas
Format: Preprint
Published: 2023
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913199820898304
author Boenisch, Franziska
Mühl, Christopher
Dziedzic, Adam
Rinberg, Roy
Papernot, Nicolas
author_facet Boenisch, Franziska
Mühl, Christopher
Dziedzic, Adam
Rinberg, Roy
Papernot, Nicolas
contents When training a machine learning model with differential privacy, one sets a privacy budget. This budget represents a maximal privacy violation that any user is willing to face by contributing their data to the training set. We argue that this approach is limited because different users may have different privacy expectations. Thus, setting a uniform privacy budget across all points may be overly conservative for some users or, conversely, not sufficiently protective for others. In this paper, we capture these preferences through individualized privacy budgets. To demonstrate their practicality, we introduce a variant of Differentially Private Stochastic Gradient Descent (DP-SGD) which supports such individualized budgets. DP-SGD is the canonical approach to training models with differential privacy. We modify its data sampling and gradient noising mechanisms to arrive at our approach, which we call Individualized DP-SGD (IDP-SGD). Because IDP-SGD provides privacy guarantees tailored to the preferences of individual users and their data points, we find it empirically improves privacy-utility trade-offs.
format Preprint
id arxiv_https___arxiv_org_abs_2303_17046
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Have it your way: Individualized Privacy Assignment for DP-SGD
Boenisch, Franziska
Mühl, Christopher
Dziedzic, Adam
Rinberg, Roy
Papernot, Nicolas
Machine Learning
Artificial Intelligence
Cryptography and Security
When training a machine learning model with differential privacy, one sets a privacy budget. This budget represents a maximal privacy violation that any user is willing to face by contributing their data to the training set. We argue that this approach is limited because different users may have different privacy expectations. Thus, setting a uniform privacy budget across all points may be overly conservative for some users or, conversely, not sufficiently protective for others. In this paper, we capture these preferences through individualized privacy budgets. To demonstrate their practicality, we introduce a variant of Differentially Private Stochastic Gradient Descent (DP-SGD) which supports such individualized budgets. DP-SGD is the canonical approach to training models with differential privacy. We modify its data sampling and gradient noising mechanisms to arrive at our approach, which we call Individualized DP-SGD (IDP-SGD). Because IDP-SGD provides privacy guarantees tailored to the preferences of individual users and their data points, we find it empirically improves privacy-utility trade-offs.
title Have it your way: Individualized Privacy Assignment for DP-SGD
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2303.17046