Revisiting Privacy-Utility Trade-off for DP Training with Pre-existing Knowledge

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zheng, Yu, Zhang, Wenchao, Zhang, Yonggang, Peng, Yuxiang, Song, Wei, Zhou, Kai, Du, Xiaojiang, Han, Bo
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866912519076970496
author Zheng, Yu
Zhang, Wenchao
Zhang, Yonggang
Peng, Yuxiang
Song, Wei
Zhou, Kai
Du, Xiaojiang
Han, Bo
author_facet Zheng, Yu
Zhang, Wenchao
Zhang, Yonggang
Peng, Yuxiang
Song, Wei
Zhou, Kai
Du, Xiaojiang
Han, Bo
contents Differential privacy (DP) provides a provable framework for protecting individuals by customizing a random mechanism over a privacy-sensitive dataset. Deep learning models have demonstrated privacy risks in model exposure as an established learning model unintentionally records membership-level privacy leakage. Differentially private stochastic gradient descent (DP-SGD) has been proposed to safeguard training individuals by adding random Gaussian noise to gradient updates in the backpropagation. Researchers identify that DP-SGD causes utility loss since the injected homogeneous noise can alter the gradient updates calculated at each iteration. Namely, all elements in the gradient are contaminated regardless of their importance in updating model parameters. In this work, we argue that the utility can be optimized by involving the heterogeneity of the the injected noise. Consequently, we propose a generic differential privacy framework with heterogeneous noise (DP-Hero) by defining a heterogeneous random mechanism to abstract its property. The insight of DP-Hero is to leverage the knowledge encoded in the previously trained model to guide the subsequent allocation of noise heterogeneity, thereby leveraging the statistical perturbation and achieving enhanced utility. Atop DP-Hero, we instantiate a heterogeneous version of DP-SGD, and further extend it to federated training. We conduct comprehensive experiments to verify and explain the effectiveness of the proposed DP-Hero, showing improved training accuracy compared with state-of-the-art works. Broadly, we shed light on improving the privacy-utility space by learning the noise guidance from the pre-existing leaked knowledge encoded in the previously trained model, showing a different perspective of understanding the utility-improved DP training.
format Preprint
id arxiv_https___arxiv_org_abs_2409_03344
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Revisiting Privacy-Utility Trade-off for DP Training with Pre-existing Knowledge
Zheng, Yu
Zhang, Wenchao
Zhang, Yonggang
Peng, Yuxiang
Song, Wei
Zhou, Kai
Du, Xiaojiang
Han, Bo
Cryptography and Security
Differential privacy (DP) provides a provable framework for protecting individuals by customizing a random mechanism over a privacy-sensitive dataset. Deep learning models have demonstrated privacy risks in model exposure as an established learning model unintentionally records membership-level privacy leakage. Differentially private stochastic gradient descent (DP-SGD) has been proposed to safeguard training individuals by adding random Gaussian noise to gradient updates in the backpropagation. Researchers identify that DP-SGD causes utility loss since the injected homogeneous noise can alter the gradient updates calculated at each iteration. Namely, all elements in the gradient are contaminated regardless of their importance in updating model parameters. In this work, we argue that the utility can be optimized by involving the heterogeneity of the the injected noise. Consequently, we propose a generic differential privacy framework with heterogeneous noise (DP-Hero) by defining a heterogeneous random mechanism to abstract its property. The insight of DP-Hero is to leverage the knowledge encoded in the previously trained model to guide the subsequent allocation of noise heterogeneity, thereby leveraging the statistical perturbation and achieving enhanced utility. Atop DP-Hero, we instantiate a heterogeneous version of DP-SGD, and further extend it to federated training. We conduct comprehensive experiments to verify and explain the effectiveness of the proposed DP-Hero, showing improved training accuracy compared with state-of-the-art works. Broadly, we shed light on improving the privacy-utility space by learning the noise guidance from the pre-existing leaked knowledge encoded in the previously trained model, showing a different perspective of understanding the utility-improved DP training.
title Revisiting Privacy-Utility Trade-off for DP Training with Pre-existing Knowledge
topic Cryptography and Security
url https://arxiv.org/abs/2409.03344