Scalable Differential Privacy with Certified Robustness in Adversarial Learning

Scalable Differential Privacy with Certified Robustness in Adversarial Learning
复制标题

DOI:
--
复制
发表时间:
2019-03
期刊:
--
影响因子:
--
通讯作者:
HaiNhat Phan;M. Thai;Han Hu;R. Jin;Tong Sun;D. Dou
HaiNhat Phan;M. Thai;Han Hu;R. Jin;Tong Sun;D. Dou
中科院分区:
其他
文献类型:
--
作者:
HaiNhat Phan;M. Thai;Han Hu;R. Jin;Tong Sun;D. Dou

文献摘要

被引文献

相似文献

在本文中,我们的目标是开发一种可扩展的算法,以在深度神经网络(DNN)的对抗性学习中保护差分隐私(DP),并对对抗性示例具有经认证的鲁棒性。通过利用DP中的顺序组合理论,我们将输入空间和潜在空间随机化,以加强我们认证的鲁棒性界限。为了解决模型实用性,隐私损失和鲁棒性之间的权衡,我们设计了一个原始的对抗性目标函数,基于DP中的后处理属性,以收紧我们模型的敏感性。提出了一种新的随机批量训练,通过绕过DP DNN中的香草迭代逐批训练,将我们的机制应用于大型DNN和数据集。端到端的理论分析和评估表明,我们的机制显着提高了DP DNN的鲁棒性和可扩展性。
In this paper, we aim to develop a scalable algorithm to preserve differential privacy (DP) in adversarial learning for deep neural networks (DNNs), with certified robustness to adversarial examples. By leveraging the sequential composition theory in DP, we randomize both input and latent spaces to strengthen our certified robustness bounds. To address the trade-off among model utility, privacy loss, and robustness, we design an original adversarial objective function, based on the post-processing property in DP, to tighten the sensitivity of our model. A new stochastic batch training is proposed to apply our mechanism on large DNNs and datasets, by bypassing the vanilla iterative batch-by-batch training in DP DNNs. An end-to-end theoretical analysis and evaluations show that our mechanism notably improves the robustness and scalability of DP DNNs.