Training with Differential Privacy: A Gradient-Preserving Noise Reduction Approach with Provable Security

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Wang, Haodi, Jiang, Tangyu, Guo, Yu, Cai, Chengjun, Wang, Cong, Jia, Xiaohua
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866915190358933504
author Wang, Haodi
Jiang, Tangyu
Guo, Yu
Cai, Chengjun
Wang, Cong
Jia, Xiaohua
author_facet Wang, Haodi
Jiang, Tangyu
Guo, Yu
Cai, Chengjun
Wang, Cong
Jia, Xiaohua
contents Deep learning models have been extensively adopted in various regions due to their ability to represent hierarchical features, which highly rely on the training set and procedures. Thus, protecting the training process and deep learning algorithms is paramount in privacy preservation. Although Differential Privacy (DP) as a powerful cryptographic primitive has achieved satisfying results in deep learning training, the existing schemes still fall short in preserving model utility, i.e., they either invoke a high noise scale or inevitably harm the original gradients. To address the above issues, in this paper, we present a more robust and provably secure approach for differentially private training called GReDP. Specifically, we compute the model gradients in the frequency domain and adopt a new approach to reduce the noise level. Unlike previous work, our GReDP only requires half of the noise scale compared to DPSGD [1] while keeping all the gradient information intact. We present a detailed analysis of our method both theoretically and empirically. The experimental results show that our GReDP works consistently better than the baselines on all models and training settings.
format Preprint
id arxiv_https___arxiv_org_abs_2409_11663
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Training with Differential Privacy: A Gradient-Preserving Noise Reduction Approach with Provable Security
Wang, Haodi
Jiang, Tangyu
Guo, Yu
Cai, Chengjun
Wang, Cong
Jia, Xiaohua
Cryptography and Security
Artificial Intelligence
Deep learning models have been extensively adopted in various regions due to their ability to represent hierarchical features, which highly rely on the training set and procedures. Thus, protecting the training process and deep learning algorithms is paramount in privacy preservation. Although Differential Privacy (DP) as a powerful cryptographic primitive has achieved satisfying results in deep learning training, the existing schemes still fall short in preserving model utility, i.e., they either invoke a high noise scale or inevitably harm the original gradients. To address the above issues, in this paper, we present a more robust and provably secure approach for differentially private training called GReDP. Specifically, we compute the model gradients in the frequency domain and adopt a new approach to reduce the noise level. Unlike previous work, our GReDP only requires half of the noise scale compared to DPSGD [1] while keeping all the gradient information intact. We present a detailed analysis of our method both theoretically and empirically. The experimental results show that our GReDP works consistently better than the baselines on all models and training settings.
title Training with Differential Privacy: A Gradient-Preserving Noise Reduction Approach with Provable Security
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2409.11663