Learning with Differential Privacy: Stability, Learnability and the Sufficiency and Necessity of ERM Principle
arXiv:1502.06309
Abstract
While machine learning has proven to be a powerful data-driven solution to many real-life problems, its use in sensitive domains has been limited due to privacy concerns. A popular approach known as **differential privacy** offers provable privacy guarantees, but it is often observed in practice that it could substantially hamper learning accuracy. In this paper we study the learnability (whether a problem can be learned by any algorithm) under Vapnik's general learning setting with differential privacy constraint, and reveal some intricate relationships between privacy, stability and learnability. In particular, we show that a problem is privately learnable **if an only if** there is a private algorithm that asymptotically minimizes the empirical risk (AERM). In contrast, for non-private learning AERM alone is not sufficient for learnability. This result suggests that when searching for private learning algorithms, we can restrict the search to algorithms that are AERM. In light of this, we propose a conceptual procedure that always finds a universally consistent algorithm whenever the problem is learnable under privacy constraint. We also propose a generic and practical algorithm and show that under very general conditions it privately learns a wide class of learning problems. Lastly, we extend some of the results to the more practical -differential privacy and establish the existence of a phase-transition on the class of problems that are approximately privately learnable with respect to how small needs to be.
to appear, Journal of Machine Learning Research, 2016
References in corpus (2)
Cited by in corpus (14)
- Generalization in Adaptive Data Analysis and Holdout Reuse
- Learning Anonymized Representations with Adversarial Neural Networks
- Generalization in Generative Adversarial Networks: A Novel Perspective from Privacy Protection
- Sharper bounds for uniformly stable algorithms
- Differentially Private Empirical Risk Minimization Revisited: Faster and More General
- DP-LSSGD: A Stochastic Optimization Method to Lift the Utility in Privacy-Preserving ERM
- Differentially Private Federated Learning with Laplacian Smoothing
- A New Approach to Adaptive Data Analysis and Learning via Maximal Leakage
- On the Privacy Properties of GAN-generated Samples
- Upper Bounds on the Generalization Error of Private Algorithms for Discrete Data
- Revisiting Model-Agnostic Private Learning: Faster Rates and Active Learning
- Selective Ensembles for Consistent Predictions
- Accuracy Gains from Privacy Amplification Through Sampling for Differential Privacy
- Stability Enhanced Privacy and Applications in Private Stochastic Gradient Descent