Binary Classification under Local Label Differential Privacy Using Randomized Response Mechanisms
Binary Classification under Local Label Differential Privacy Using Randomized Response Mechanisms
复制标题
DOI:
--
复制
发表时间:
--
期刊:
影响因子:
--
通讯作者:
Shi Xu;Chendi Wang;W. Sun;Guang Cheng
中科院分区:
文献类型:
--
作者:
Shi Xu;Chendi Wang;W. Sun;Guang Cheng
Label differential privacy is a popular branch of ϵ -differential privacy for protecting labels in training datasets with non-private features. In this paper, we study the generalization performance of a binary classifier trained on a dataset privatized under the label differential privacy achieved by the randomized response mechanism. Particularly, we establish minimax lower bounds for the excess risks of the deep neural network plug-in classifier, theoretically quantifying how privacy guarantee ϵ affects its generalization performance. Our theoretical result shows: (1) the randomized response mechanism slows down the convergence of excess risk by lessening the multiplicative constant term compared with the non-private case ( ϵ = ∞ ); (2) as ϵ decreases, the optimal structure of the neural network should be smaller for better generalization performance; (3) the convergence of its excess risk is guaranteed even if ϵ is adaptive to the size of training sample n at a rate slower than O ( n − 1 / 2 ). Our theoretical results are validated by extensive simulated examples and two real applications.