Abstract
Differential privacy is a widely accepted measure of privacy in the context of deep learning algorithms, and achieving it relies on a noisy training approach known as differentially private stochastic gradient descent (DP-SGD). DP-SGD requires direct noise addition to every gradient in a dense neural network, the privacy is achieved at a significant utility cost. In this work, we present Spectral-DP, a new differentially private learning approach which combines gradient perturbation in the spectral domain with spectral filtering to achieve a desired privacy guarantee with a lower noise scale and thus better utility. We develop differentially private deep learning methods based on Spectral-DP for architectures that contain both convolution and fully connected layers. In particular, for fully connected layers, we combine a block-circulant based spatial restructuring with Spectral-DP to achieve better utility. Through comprehensive experiments, we study and provide guidelines to implement Spectral-DP deep learning on benchmark datasets. In comparison with state-of-the-art DP-SGD based approaches, Spectral-DP is shown to have uniformly better utility performance in both training from scratch and transfer learning settings.
| Original language | English (US) |
|---|---|
| Title of host publication | Proceedings - 44th IEEE Symposium on Security and Privacy, SP 2023 |
| Publisher | Institute of Electrical and Electronics Engineers Inc. |
| Pages | 1944-1960 |
| Number of pages | 17 |
| ISBN (Electronic) | 9781665493369 |
| DOIs | |
| State | Published - 2023 |
| Externally published | Yes |
| Event | 44th IEEE Symposium on Security and Privacy, SP 2023 - Hybrid, San Francisco, United States Duration: May 22 2023 → May 25 2023 |
Publication series
| Name | Proceedings - IEEE Symposium on Security and Privacy |
|---|---|
| Volume | 2023-May |
| ISSN (Print) | 1081-6011 |
Conference
| Conference | 44th IEEE Symposium on Security and Privacy, SP 2023 |
|---|---|
| Country/Territory | United States |
| City | Hybrid, San Francisco |
| Period | 5/22/23 → 5/25/23 |
Bibliographical note
Publisher Copyright:© 2023 IEEE.
Fingerprint
Dive into the research topics of 'Spectral-DP: Differentially Private Deep Learning through Spectral Perturbation and Filtering'. Together they form a unique fingerprint.Cite this
- APA
- Standard
- Harvard
- Vancouver
- Author
- BIBTEX
- RIS