Disparate Impact on Group Accuracy of Linearization for Private Inference

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Das, Saswat, Romanelli, Marco, Fioretto, Ferdinando
Format: Preprint
Published: 2024
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866916362310385664
author Das, Saswat
Romanelli, Marco
Fioretto, Ferdinando
author_facet Das, Saswat
Romanelli, Marco
Fioretto, Ferdinando
contents Ensuring privacy-preserving inference on cryptographically secure data is a well-known computational challenge. To alleviate the bottleneck of costly cryptographic computations in non-linear activations, recent methods have suggested linearizing a targeted portion of these activations in neural networks. This technique results in significantly reduced runtimes with often negligible impacts on accuracy. In this paper, we demonstrate that such computational benefits may lead to increased fairness costs. Specifically, we find that reducing the number of ReLU activations disproportionately decreases the accuracy for minority groups compared to majority groups. To explain these observations, we provide a mathematical interpretation under restricted assumptions about the nature of the decision boundary, while also showing the prevalence of this problem across widely used datasets and architectures. Finally, we show how a simple procedure altering the fine-tuning step for linearized models can serve as an effective mitigation strategy.
format Preprint
id arxiv_https___arxiv_org_abs_2402_03629
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Disparate Impact on Group Accuracy of Linearization for Private Inference
Das, Saswat
Romanelli, Marco
Fioretto, Ferdinando
Machine Learning
Cryptography and Security
Computers and Society
Ensuring privacy-preserving inference on cryptographically secure data is a well-known computational challenge. To alleviate the bottleneck of costly cryptographic computations in non-linear activations, recent methods have suggested linearizing a targeted portion of these activations in neural networks. This technique results in significantly reduced runtimes with often negligible impacts on accuracy. In this paper, we demonstrate that such computational benefits may lead to increased fairness costs. Specifically, we find that reducing the number of ReLU activations disproportionately decreases the accuracy for minority groups compared to majority groups. To explain these observations, we provide a mathematical interpretation under restricted assumptions about the nature of the decision boundary, while also showing the prevalence of this problem across widely used datasets and architectures. Finally, we show how a simple procedure altering the fine-tuning step for linearized models can serve as an effective mitigation strategy.
title Disparate Impact on Group Accuracy of Linearization for Private Inference
topic Machine Learning
Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2402.03629