CRII: SaTC: PrivateNet - Preserving Differential Privacy in Deep Learning under Model Attacks
CRII: SaTC: PrivateNet - Preserving Differential Privacy in Deep Learning under Model Attacks
批准号:
1850094
负责人:
Hai Phan
金额:
$17.4万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-02-15 至 2023-01-31
中文摘要
机器学习在医疗保健领域的快速发展带来了明显的隐私问题,当深度神经网络和其他模型基于患者的个人和高度敏感的数据(如临床记录或跟踪的健康数据)构建时。 此外,这些模型可能容易受到攻击者的攻击,攻击者试图推断用于构建模型的敏感数据。 这就提出了重要的研究问题,即如何开发机器学习模型,保护私人数据免受推理攻击,同时仍然是准确和有用的预测模型,以及重要的实际考虑因素,即患者数据的这些风险如何使医疗保健提供者面临基于HIPAA和相关法规的法律的行动。为了解决这些问题,该项目将开发一个名为PrivateNet的框架,用于在模型攻击下保护深度神经网络的隐私,为深度学习中使用的数据提供强大的隐私保护。 PrivateNet将在常用的机器学习框架之上开发,为项目的研究结果在行业和教育环境中产生影响提供方法。该项目的一个关键目标是更好地理解和防御模型推理攻击,包括众所周知的基本模型攻击和通过经典机密性和完整性模型的棱镜开发的新型攻击。 通过对这些攻击的广泛分析,该团队将了解学习方法关键方面的相对风险。 特别是,脆弱的功能,参数和相关性,这是必不可少的进行模型攻击,将自动识别和保护的一种新的威胁感知的隐私保护方法的基础上,从差分隐私的想法。 具体而言,该团队将开发自适应隐私保护机制,将噪声分布在学习过程中最脆弱的方面,以在深度学习模型中提供强大的差异隐私保护,同时保持高模型实用性。 该项目有望为在模型攻击下保护深度学习中用户个人和高度敏感数据的关键隐私保护技术奠定基础。该奖项反映了NSF的法定使命,通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The rapid development of machine learning in the domain of healthcare presents clear privacy issues, when deep neural networks and other models are built based on patients' personal and highly sensitive data such as clinical records or tracked health data. Further, these models can be vulnerable to attackers trying to infer the sensitive data that was used to build the model. This raises important research questions about how to develop machine learning models that protect private data against inference attacks while still being accurate and useful predictive models, as well as important practical considerations about how these risks to patient data may expose health care providers to legal action based on HIPAA and related regulations. To address these questions, this project will develop a framework, called PrivateNet, for privacy preservation in deep neural networks under model attacks to offer strong privacy protections for data used in deep learning. PrivateNet will be developed on top of commonly used machine learning frameworks, providing ways for the project's findings to have impact in both industry and educational contexts.A key thrust of the project is to better understand and defend against model inference attacks, including both well-known fundamental model attacks and novel attacks developed through prism of the classical confidentiality and integrity models. Through an extensive analysis of these attacks, the team will develop an understanding of the relative risks of key aspects of learning approaches. In particular, vulnerable features, parameters, and correlations, which are essential to conduct model attacks, will be automatically identified and protected in a novel threat-aware privacy preserving approach based on ideas from differential privacy. Specifically, the team will develop adaptive privacy preserving mechanisms that distribute noise across the most vulnerable aspects of the learning process to provide strong differential privacy protections in deep learning models while maintaining high model utility. The project is expected to lay a foundation of key privacy-preserving techniques to protect users' personal and highly sensitive data in deep learning under model attacks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(12)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.24963/ijcai.2019/660
发表时间:
2019-06
期刊:
ArXiv
影响因子:
--
作者:
[Nhathai Phan;Minh N. Vu;Yang Liu;R. Jin;D. Dou;Xintao Wu;M. Thai]
通讯作者:
Nhathai Phan;Minh N. Vu;Yang Liu;R. Jin;D. Dou;Xintao Wu;M. Thai
DrugTracker: A Community-focused Drug Abuse Monitoring and Supporting System using Social Media and Geospatial Data (Demo Paper)
DrugTracker:使用社交媒体和地理空间数据的以社区为中心的药物滥用监测和支持系统(演示论文)
DOI:
10.1145/3347146.3359076
发表时间:
2019
期刊:
Proceedings of the 27th ACM SIGSPATIAL International Conference on Advances in Geographic Information Systems
影响因子:
--
作者:
[Hu, Han, Phan, NhatHai, Ye, Xinyue, Jin, Ruoming, Ding, Kele, Dou, Dejing, Vo, Huy T.]
通讯作者:
Vo, Huy T.
DOI:
10.1109/ijcnn48605.2020.9206753
发表时间:
2020-04
期刊:
2020 International Joint Conference on Neural Networks (IJCNN)
影响因子:
--
作者:
[Phung Lai;Nhathai Phan;Han Hu;Anuja Badeti;David Newman;D. Dou]
通讯作者:
Phung Lai;Nhathai Phan;Han Hu;Anuja Badeti;David Newman;D. Dou
DOI:
10.1109/bigdata52589.2021.9671964
发表时间:
2021-09
期刊:
2021 IEEE International Conference on Big Data (Big Data)
影响因子:
--
作者:
[Guanxiong Liu;Issa M. Khalil;Abdallah Khreishah;Nhathai Phan]
通讯作者:
Guanxiong Liu;Issa M. Khalil;Abdallah Khreishah;Nhathai Phan
Differentially Private Lifelong Learning
差异化私人终身学习
DOI:
--
发表时间:
2019
期刊:
NeurIPS'19 Workshop
影响因子:
--
作者:
[NhatHai Phan, My T.]
通讯作者:
NhatHai Phan, My T.
共 9 条
SaTC: CORE: Small: Collaborative: When Adversarial Learning Meets Differential Privacy: Theoretical Foundation and Applications
-
批准号:1935928
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2020
-
负责人:Hai Phan
-
依托单位:
EAGER: Collaborative Research: Understanding Human Behaviors and Mental Health using Federated Machine Learning on Smart Phones
-
批准号:2041096
-
项目类别:Standard Grant
-
资助金额:$7.5万
-
财政年份:2020
-
负责人:Hai Phan
-
依托单位:
海外基金