Private Prediction Sets

Private Prediction Sets
复制标题

DOI:
10.1162/99608f92.16c71dad
复制
发表时间:
2021-02
期刊:
ArXiv
影响因子:
--
通讯作者:
Anastasios Nikolas Angelopoulos;Stephen Bates;Tijana Zrnic;Michael I. Jordan
Anastasios Nikolas Angelopoulos;Stephen Bates;Tijana Zrnic;Michael I. Jordan
中科院分区:
其他
文献类型:
--
作者:
Anastasios Nikolas Angelopoulos;Stephen Bates;Tijana Zrnic;Michael I. Jordan

文献摘要

相似文献

在涉及后续决策的现实环境中,机器学习系统的部署通常需要可靠的不确定性量化和保护个人隐私。我们提出了一个框架,共同对待这两个必要的。我们的框架基于共形预测,这是一种增强预测模型以返回提供不确定性量化的预测集的方法-它们可证明以用户指定的概率(例如90%)覆盖真实响应。人们可能希望,当与私人训练的模型一起使用时,共形预测将为最终的预测集提供隐私保证;不幸的是,情况并非如此。为了解决这个关键问题,我们开发了一种方法,该方法采用任何预先训练的预测模型并输出差异化的私有预测集。我们的方法遵循分裂共形预测的一般方法;我们使用保留数据来校准预测集的大小,但通过使用私有化分位数子例程来保护隐私。该子例程补偿为了保护隐私而引入的噪声,以保证正确的覆盖。我们在大规模计算机视觉数据集上评估了该方法。
In real-world settings involving consequential decision-making, the deployment of machine learning systems generally requires both reliable uncertainty quantification and protection of individuals' privacy. We present a framework that treats these two desiderata jointly. Our framework is based on conformal prediction, a methodology that augments predictive models to return prediction sets that provide uncertainty quantification -- they provably cover the true response with a user-specified probability, such as 90%. One might hope that when used with privately-trained models, conformal prediction would yield privacy guarantees for the resulting prediction sets; unfortunately, this is not the case. To remedy this key problem, we develop a method that takes any pre-trained predictive model and outputs differentially private prediction sets. Our method follows the general approach of split conformal prediction; we use holdout data to calibrate the size of the prediction sets but preserve privacy by using a privatized quantile subroutine. This subroutine compensates for the noise introduced to preserve privacy in order to guarantee correct coverage. We evaluate the method on large-scale computer vision datasets.