Minimax Filter: Learning to Preserve Privacy from Inference Attacks
arXiv:1610.03577
Abstract
Preserving privacy of continuous and/or high-dimensional data such as images, videos and audios, can be challenging with syntactic anonymization methods which are designed for discrete attributes. Differential privacy, which provides a more formal definition of privacy, has shown more success in sanitizing continuous data. However, both syntactic and differential privacy are susceptible to inference attacks, i.e., an adversary can accurately infer sensitive attributes from sanitized data. The paper proposes a novel filter-based mechanism which preserves privacy of continuous and high-dimensional attributes against inference attacks. Finding the optimal utility-privacy tradeoff is formulated as a min-diff-max optimization problem. The paper provides an ERM-like analysis of the generalization error and also a practical algorithm to perform the optimization. In addition, the paper proposes an extension that combines minimax filter and differentially-private noisy mechanism. Advantages of the method over purely noisy mechanisms is explained and demonstrated with examples. Experiments with several real-world tasks including facial expression classification, speech emotion classification, and activity classification from motion, show that the minimax filter can simultaneously achieve similar or better target task accuracy and lower inference accuracy, often significantly lower than previous methods.
Revision 2: minor revision
References in corpus (2)
Cited by in corpus (18)
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning
- Mobile Sensor Data Anonymization
- A Study of Face Obfuscation in ImageNet
- Generative Adversarial Privacy
- Inherent Tradeoffs in Learning Fair Representations
- Towards Privacy-Preserving Visual Recognition via Adversarial Training: A Pilot Study
- Understanding Compressive Adversarial Privacy
- PCAL: A Privacy-preserving Intelligent Credit Risk Modeling Framework Based on Adversarial Learning
- Fundamental Limits and Tradeoffs in Invariant Representation Learning
- Trade-offs and Guarantees of Adversarial Representation Learning for Information Obfuscation
- Application-driven Privacy-preserving Data Publishing with Correlated Attributes
- Unsupervised Information Obfuscation for Split Inference of Neural Networks
- Machine vs Machine: Minimax-Optimal Defense Against Adversarial Examples
- Distributed generation of privacy preserving data with user customization
- Generating private data with user customization
- Maximal Information Leakage based Privacy Preserving Data Disclosure Mechanisms
- Finding Solutions to Generative Adversarial Privacy
- An adversarial learning framework for preserving users' anonymity in face-based emotion recognition