Learning to be adversarially robust and differentially private

01/06/2022
by   Jamie Hayes, et al.
0

We study the difficulties in learning that arise from robust and differentially private optimization. We first study convergence of gradient descent based adversarial training with differential privacy, taking a simple binary classification task on linearly separable data as an illustrative example. We compare the gap between adversarial and nominal risk in both private and non-private settings, showing that the data dimensionality dependent term introduced by private optimization compounds the difficulties of learning a robust model. After this, we discuss what parts of adversarial training and differential privacy hurt optimization, identifying that the size of adversarial perturbation and clipping norm in differential privacy both increase the curvature of the loss landscape, implying poorer generalization performance.

READ FULL TEXT
research
10/20/2017

Differentially Private Empirical Risk Minimization with Input Perturbation

We propose a novel framework for the differentially private ERM, input p...
research
12/10/2019

Classification under local differential privacy

We consider the binary classification problem in a setup that preserves ...
research
01/16/2023

Enforcing Privacy in Distributed Learning with Performance Guarantees

We study the privatization of distributed learning and optimization stra...
research
11/30/2020

Robust and Private Learning of Halfspaces

In this work, we study the trade-off between differential privacy and ad...
research
05/13/2019

Differentially Private Empirical Risk Minimization with Sparsity-Inducing Norms

Differential privacy is concerned about the prediction quality while mea...
research
12/25/2020

Robustness, Privacy, and Generalization of Adversarial Training

Adversarial training can considerably robustify deep neural networks to ...
research
12/14/2020

Robustness Threats of Differential Privacy

Differential privacy is a powerful and gold-standard concept of measurin...

Please sign up or login with your details

Forgot password? Click here to reset