Auditing Differentially Private Machine Learning: How Private is Private SGD?

Auditing Differentially Private Machine Learning: How Private is Private SGD?
复制标题

DOI:
--
复制
发表时间:
2020-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Matthew Jagielski;Jonathan Ullman;Alina Oprea
Matthew Jagielski;Jonathan Ullman;Alina Oprea
中科院分区:
其他
文献类型:
--
作者:
Matthew Jagielski;Jonathan Ullman;Alina Oprea

文献摘要

被引文献

相似文献

我们研究差分隐私随机梯度下降(Differentially Private SGD)在实践中是否提供了比其最先进的分析所保证的更好的隐私。我们通过新颖的数据投毒攻击来进行研究,我们表明这种攻击对应于现实的隐私攻击。虽然先前的工作(Ma等人,arXiv 2019)提出了差分隐私和数据投毒之间的这种联系作为对数据投毒的一种防御,但我们将其用作理解特定机制隐私的工具是新的。更广泛地说,我们的工作采用一种定量的、实证的方法来理解差分隐私算法特定实现所提供的隐私,我们认为这种方法有可能补充和影响关于差分隐私的分析工作。
We investigate whether Differentially Private SGD offers better privacy in practice than what is guaranteed by its state-of-the-art analysis. We do so via novel data poisoning attacks, which we show correspond to realistic privacy attacks. While previous work (Ma et al., arXiv 2019) proposed this connection between differential privacy and data poisoning as a defense against data poisoning, our use as a tool for understanding the privacy of a specific mechanism is new. More generally, our work takes a quantitative, empirical approach to understanding the privacy afforded by specific implementations of differentially private algorithms that we believe has the potential to complement and influence analytical work on differential privacy.