Privacy for Free: Posterior Sampling and Stochastic Gradient Monte Carlo
arXiv:1502.07645
Abstract
We consider the problem of Bayesian learning on sensitive datasets and present two simple but somewhat surprising results that connect Bayesian learning to "differential privacy:, a cryptographic approach to protect individual-level privacy while permiting database-level utility. Specifically, we show that that under standard assumptions, getting one single sample from a posterior distribution is differentially private "for free". We will see that estimator is statistically consistent, near optimal and computationally tractable whenever the Bayesian model of interest is consistent, optimal and tractable. Similarly but separately, we show that a recent line of works that use stochastic gradient for Hybrid Monte Carlo (HMC) sampling also preserve differentially privacy with minor or no modifications of the algorithmic procedure at all, these observations lead to an "anytime" algorithm for Bayesian learning under privacy constraint. We demonstrate that it performs much better than the state-of-the-art differential private methods on synthetic and real datasets.
References in corpus (3)
Cited by in corpus (10)
- Generalization in Generative Adversarial Networks: A Novel Perspective from Privacy Protection
- Reviewing and Improving the Gaussian Mechanism for Differential Privacy
- Tighter Generalization Bounds for Iterative Differentially Private Learning Algorithms
- Differentially Private Convex Optimization with Feasibility Guarantees
- Secure and Differentially Private Bayesian Learning on Distributed Data
- Locally Differentially Private Bayesian Inference
- PD-ML-Lite: Private Distributed Machine Learning from Lighweight Cryptography
- N-grams Bayesian Differential Privacy
- Stability Enhanced Privacy and Applications in Private Stochastic Gradient Descent
- On Privacy Protection of Latent Dirichlet Allocation Model Training