A Critical Review on the Use (and Misuse) of Differential Privacy in Machine Learning
arXiv:2206.04621 · doi:10.1145/3547139
Abstract
We review the use of differential privacy (DP) for privacy protection in machine learning (ML). We show that, driven by the aim of preserving the accuracy of the learned models, DP-based ML implementations are so loose that they do not offer the ex ante privacy guarantees of DP. Instead, what they deliver is basically noise addition similar to the traditional (and often criticized) statistical disclosure control approach. Due to the lack of formal privacy guarantees, the actual level of privacy offered must be experimentally assessed ex post, which is done very seldom. In this respect, we present empirical results showing that standard anti-overfitting techniques in ML can achieve a better utility/privacy/efficiency trade-off than DP.
ACM Computing Surveys (to appear)
References in corpus (3)
Cited by in corpus (6)
- How to DP-fy ML: A Practical Guide to Machine Learning with Differential Privacy
- Recent Advances of Differential Privacy in Centralized Deep Learning: A Systematic Survey
- Enhanced Security and Privacy via Fragmented Federated Learning
- Towards integration of Privacy Enhancing Technologies in Explainable Artificial Intelligence
- Noise Variance Optimization in Differential Privacy: A Game-Theoretic Approach Through Per-Instance Differential Privacy
- Why Data Anonymization Has Not Taken Off