Exploring the Unfairness of DP-SGD Across Settings
arXiv:2202.12058
Abstract
End users and regulators require private and fair artificial intelligence models, but previous work suggests these objectives may be at odds. We use the CivilComments to evaluate the impact of applying the {\em de facto} standard approach to privacy, DP-SGD, across several fairness metrics. We evaluate three implementations of DP-SGD: for dimensionality reduction (PCA), linear classification (logistic regression), and robust deep learning (Group-DRO). We establish a negative, logarithmic correlation between privacy and fairness in the case of linear classification and robust deep learning. DP-SGD had no significant impact on fairness for PCA, but upon inspection, also did not seem to lead to private representations.
6 pages, 3 figures, https://aaai-ppai22.github.io/
References in corpus (5)
- Distributionally Robust Neural Networks for Group Shifts: On the Importance of Regularization for Worst-Case Generalization
- WILDS: A Benchmark of in-the-Wild Distribution Shifts
- Diffprivlib: The IBM Differential Privacy Library
- Fairness risk measures
- Assessing Fairness in Classification Parity of Machine Learning Models in Healthcare