Nowadays, owners and developers of deep learning models must consider stringent privacy-preservation rules of their training data, usually crowd-sourced and retaining sensitive information. The most widely adopted method to enforce privacy guarantees of a deep learning model nowadays relies on optimization techniques enforcing differential privacy. According to the literature, this approach has proven to be a successful defence against several models’ privacy attacks, but its downside is a substantial degradation of the models’ performance. In this work, we compare the effectiveness of the differentially-private stochastic gradient descent (DP-SGD) algorithm against standard optimization practices with regularization techniques. We analyze the resulting models’ utility, training performance, and the effectiveness of membership inference and model inversion attacks against the learned models. Finally, we discuss differential privacy’s flaws and limits and empirically demonstrate the often superior privacy-preserving properties of dropout and l2-regularization.

On the utility and protection of optimization with differential privacy and classic regularization techniques

Eugenio Lomurno;Matteo Matteucci
2023-01-01

Abstract

Nowadays, owners and developers of deep learning models must consider stringent privacy-preservation rules of their training data, usually crowd-sourced and retaining sensitive information. The most widely adopted method to enforce privacy guarantees of a deep learning model nowadays relies on optimization techniques enforcing differential privacy. According to the literature, this approach has proven to be a successful defence against several models’ privacy attacks, but its downside is a substantial degradation of the models’ performance. In this work, we compare the effectiveness of the differentially-private stochastic gradient descent (DP-SGD) algorithm against standard optimization practices with regularization techniques. We analyze the resulting models’ utility, training performance, and the effectiveness of membership inference and model inversion attacks against the learned models. Finally, we discuss differential privacy’s flaws and limits and empirically demonstrate the often superior privacy-preserving properties of dropout and l2-regularization.
2023
Machine Learning, Optimization, and Data Science. LOD 2022
File in questo prodotto:
File Dimensione Formato  
_Preprint__On_the_utility_and_protection_of_optimization_with_differential_privacy_and_classic_regularization_techniques.pdf

accesso aperto

: Pre-Print (o Pre-Refereeing)
Dimensione 810.12 kB
Formato Adobe PDF
810.12 kB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11311/1220549
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? 0
social impact