Heterogeneous Gaussian Mechanism: Preserving Differential Privacy in Deep Learning with Provable Robustness

Heterogeneous Gaussian Mechanism: Preserving Differential Privacy in Deep Learning with Provable Robustness
复制标题

DOI:
10.24963/ijcai.2019/660
复制
发表时间:
2019-06
期刊:
ArXiv
影响因子:
--
通讯作者:
Nhathai Phan;Minh N. Vu;Yang Liu;R. Jin;D. Dou;Xintao Wu;M. Thai
Nhathai Phan;Minh N. Vu;Yang Liu;R. Jin;D. Dou;Xintao Wu;M. Thai
中科院分区:
其他
文献类型:
--
作者:
Nhathai Phan;Minh N. Vu;Yang Liu;R. Jin;D. Dou;Xintao Wu;M. Thai

文献摘要

相似文献

在本文中,我们提出了一种新的异构高斯机制(HGM)来保护深度神经网络中的差分隐私,并具有可证明的对抗性示例的鲁棒性。首先将传统高斯机制中的隐私预算约束从(0,1]放宽到(0,infty),并引入新的噪声尺度约束以保持差分隐私。在我们的机制中的噪声可以任意重新分配,提供了一个独特的能力,以解决模型效用和隐私损失之间的权衡。为了获得可证明的鲁棒性,我们的HGM被应用于将高斯噪声注入到第一隐藏层中。然后,提出了一个更严格的鲁棒性界。理论分析和全面评估表明,与基线方法相比,我们的机制显着提高了差分私有深度神经网络在各种模型攻击下的鲁棒性。
In this paper, we propose a novel Heterogeneous Gaussian Mechanism (HGM) to preserve differential privacy in deep neural networks, with provable robustness against adversarial examples. We first relax the constraint of the privacy budget in the traditional Gaussian Mechanism from (0, 1] to (0, infty), with a new bound of the noise scale to preserve differential privacy. The noise in our mechanism can be arbitrarily redistributed, offering a distinctive ability to address the trade-off between model utility and privacy loss. To derive provable robustness, our HGM is applied to inject Gaussian noise into the first hidden layer. Then, a tighter robustness bound is proposed. Theoretical analysis and thorough evaluations show that our mechanism notably improves the robustness of differentially private deep neural networks, compared with baseline approaches, under a variety of model attacks.