Binary Classification under Local Label Differential Privacy Using Randomized Response Mechanisms

Binary Classification under Local Label Differential Privacy Using Randomized Response Mechanisms
复制标题

DOI:
--
复制
发表时间:
--
期刊:
--
影响因子:
--
通讯作者:
Shi Xu;Chendi Wang;W. Sun;Guang Cheng
Shi Xu;Chendi Wang;W. Sun;Guang Cheng
中科院分区:
其他
文献类型:
--
作者:
Shi Xu;Chendi Wang;W. Sun;Guang Cheng

文献摘要

相似文献

标签差异隐私是在本文中保护具有非私人功能的培训数据集中标签的流行分支。随机响应机制。我们为深度神经网络分类器的多余风险建立了最小值,理论上量化了隐私保证如何影响我们的理论结果。与非私有化的情况相比,通过减少乘法恒定项(ϵ =∞)来收敛即使以比O(n -1/2)慢的训练样本n适应训练样本n的大小,也可以保证其多余的风险。
Label differential privacy is a popular branch of ϵ -differential privacy for protecting labels in training datasets with non-private features. In this paper, we study the generalization performance of a binary classifier trained on a dataset privatized under the label differential privacy achieved by the randomized response mechanism. Particularly, we establish minimax lower bounds for the excess risks of the deep neural network plug-in classifier, theoretically quantifying how privacy guarantee ϵ affects its generalization performance. Our theoretical result shows: (1) the randomized response mechanism slows down the convergence of excess risk by lessening the multiplicative constant term compared with the non-private case ( ϵ = ∞ ); (2) as ϵ decreases, the optimal structure of the neural network should be smaller for better generalization performance; (3) the convergence of its excess risk is guaranteed even if ϵ is adaptive to the size of training sample n at a rate slower than O ( n − 1 / 2 ). Our theoretical results are validated by extensive simulated examples and two real applications.