Differentially Private Learning Needs Better Features (or Much More Data)

11/23/2020
by   Florian Tramèr, et al.
0

We demonstrate that differentially private machine learning has not yet reached its "AlexNet moment" on many canonical vision tasks: linear models trained on handcrafted features significantly outperform end-to-end deep neural networks for moderate privacy budgets. To exceed the performance of handcrafted features, we show that private learning requires either much more private data, or access to features learned on public data from a similar domain. Our work introduces simple yet strong baselines for differentially private learning that can inform the evaluation of future progress in this area.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
10/08/2020

Differentially Private Deep Learning with Direct Feedback Alignment

Standard methods for differentially private training of deep neural netw...
research
01/29/2019

Representation Transfer for Differentially Private Drug Sensitivity Prediction

Motivation: Human genomic datasets often contain sensitive information t...
research
02/18/2019

Differentially Private Continual Learning

Catastrophic forgetting can be a significant problem for institutions th...
research
05/25/2018

An end-to-end Differentially Private Latent Dirichlet Allocation Using a Spectral Algorithm

Latent Dirichlet Allocation (LDA) is a powerful probabilistic model used...
research
08/08/2019

Local Differential Privacy for Deep Learning

Deep learning (DL) is a promising area of machine learning which is beco...
research
10/16/2022

A General Framework for Auditing Differentially Private Machine Learning

We present a framework to statistically audit the privacy guarantee conf...
research
03/21/2020

Weighted directed networks with a differentially private bi-degree sequence

The p_0 model is an exponential random graph model for directed networks...

Please sign up or login with your details

Forgot password? Click here to reset