Differentially Private Empirical Risk Minimization
arXiv:0912.0071
Abstract
Privacy-preserving machine learning algorithms are crucial for the increasingly common setting in which personal data, such as medical or financial records, are analyzed. We provide general techniques to produce privacy-preserving approximations of classifiers learned via (regularized) empirical risk minimization (ERM). These algorithms are private under the -differential privacy definition due to Dwork et al. (2006). First we apply the output perturbation ideas of Dwork et al. (2006), to ERM classification. Then we propose a new method, objective perturbation, for privacy-preserving machine learning algorithm design. This method entails perturbing the objective function before optimizing over classifiers. If the loss and regularizer satisfy certain convexity and differentiability criteria, we prove theoretical results showing that our algorithms preserve privacy, and provide generalization bounds for linear and nonlinear kernels. We further present a privacy-preserving technique for tuning the parameters in general machine learning algorithms, thereby providing end-to-end privacy guarantees for the training process. We apply these results to produce privacy-preserving analogues of regularized logistic regression and support vector machines. We obtain encouraging results from evaluating their performance on real demographic and benchmark data sets. Our results show that both theoretically and empirically, objective perturbation is superior to the previous state-of-the-art, output perturbation, in managing the inherent tradeoff between privacy and learning performance.
40 pages, 7 figures, accepted to the Journal of Machine Learning Research
References in corpus (2)
Cited by in corpus (47)
- Deep Learning with Differential Privacy
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
- Algorithms that Remember: Model Inversion Attacks and Data Protection Law
- Federated Learning with Bayesian Differential Privacy
- How to DP-fy ML: A Practical Guide to Machine Learning with Differential Privacy
- Scalable Privacy-Preserving Data Sharing Methodology for Genome-Wide Association Studies
- Privacy Amplification by Iteration
- Correlated Differential Privacy: Feature Selection in Machine Learning
- A Comprehensive Survey on Local Differential Privacy Toward Data Statistics and Analysis
- Machine Unlearning: Solutions and Challenges
- Practical Blind Membership Inference Attack via Differential Comparisons
- A Critical Review on the Use (and Misuse) of Differential Privacy in Machine Learning
- Privacy-Preserving Brain-Computer Interfaces: A Systematic Review
- Responsible and Regulatory Conform Machine Learning for Medicine: A Survey of Challenges and Solutions
- Joint Privacy Enhancement and Quantization in Federated Learning
- Privacy-preserving Distributed Machine Learning via Local Randomization and ADMM Perturbation
- DP-Forward: Fine-tuning and Inference on Language Models with Differential Privacy in Forward Pass
- Privately Solving Linear Programs
- On the Protection of Private Information in Machine Learning Systems: Two Recent Approaches
- Quantum Differentially Private Sparse Regression Learning
- Jointly Private Convex Programming
- Practical Differentially Private and Byzantine-resilient Federated Learning
- Evaluating Privacy-Preserving Machine Learning in Critical Infrastructures: A Case Study on Time-Series Classification
- A Differentially Private Framework for Deep Learning with Convexified Loss Functions
- Privacy-Preserving Push-Pull Method for Decentralized Optimization via State Decomposition
- Key Protected Classification for Collaborative Learning
- Asynchronous Distributed Learning from Constraints
- Differentially Private Multivariate Time Series Forecasting of Aggregated Human Mobility With Deep Learning: Input or Gradient Perturbation?
- Weighted Distributed Differential Privacy ERM: Convex and Non-convex
- Private Prediction Sets
- Privacy-preserving Non-negative Matrix Factorization with Outliers
- Interval Privacy: A Framework for Privacy-Preserving Data Collection
- Neither Private Nor Fair: Impact of Data Imbalance on Utility and Fairness in Differential Privacy
- Differentially Private Bayesian Inference for Generalized Linear Models
- On Mitigating the Utility-Loss in Differentially Private Learning: A new Perspective by a Geometrically Inspired Kernel Approach
- Privacy Enhancing Machine Learning via Removal of Unwanted Dependencies
- Improving the Utility of Differentially Private Clustering through Dynamical Processing
- Efficient Sparse Least Absolute Deviation Regression with Differential Privacy
- On the Privacy Risks of Deploying Recurrent Neural Networks in Machine Learning Models
- Correlation inference attacks against machine learning models
- Differentially Private Convex Optimization with Piecewise Affine Objectives
- Marich: A Query-efficient Distributionally Equivalent Model Extraction Attack using Public Data
- High-Dimensional Private Empirical Risk Minimization by Greedy Coordinate Descent
- From Noisy Fixed-Point Iterations to Private ADMM for Centralized and Federated Learning
- The Fair Game: Auditing & Debiasing AI Algorithms Over Time
- Privacy accounting conomics: Improving differential privacy composition via a posteriori bounds
- Large Margin Multiclass Gaussian Classification with Differential Privacy