Revisiting Differentially Private Regression: Lessons From Learning Theory and their Consequences
نویسندگان
چکیده
Private regression has received attention from both database and security communities. Recent work by Fredrikson et al. (USENIX Security 2014) analyzed the functional mechanism (Zhang et al. VLDB 2012) for training linear regression models over medical data. Unfortunately, they found that model accuracy is already unacceptable with differential privacy when ε = 5. We address this issue, presenting an explicit connection between differential privacy and stable learning theory through which a substantially better privacy/utility tradeoff can be obtained. Perhaps more importantly, our theory reveals that the most basic mechanism in differential privacy, output perturbation, can be used to obtain a better tradeoff for all convex-Lipschitz-bounded learning tasks. Since output perturbation is simple to implement, it means that our approach is potentially widely applicable in practice. We go on to apply it on the same medical data as used by Fredrikson et al. Encouragingly, we achieve accurate models even for ε = 0.1. In the last part of this paper, we study the impact of our improved differentially private mechanisms on model inversion attacks, a privacy attack introduced by Fredrikson et al. We observe that the improved tradeoff makes the resulting differentially private model more susceptible to inversion attacks. We analyze this phenomenon formally.
منابع مشابه
LEARNER INITIATIVES ACROSS QUESTION-ANSWER SEQUENCES: A CONVERSATION ANALYTIC ACCOUNT OF LANGUAGE CLASSROOM DISCOURSE
This paper investigates learner-initiated responses to English language teachers’ referential questions and learner initiatives after teachers’ feedback moves in meaning-focused question-answer sequences to analyze how interactional practices of language teachers, their initiation and feedback moves, facilitate learner initiatives. Classroom discourse research has largely neglected learner init...
متن کاملPublic Schools and Private Language Institutes: Any Differences in Students’ L2 Motivational Self System?
To enrich our understanding of the attitudinal/motivational basis of foreign language learning at junior high school level, this study investigated the students’ status of L2 motivation, the relationship between motivational factors, and the possibility of predicting their motivated learning behavior in light of Dörnyei’s (2005, 2009) theory of L2 Motivational Self System. To this end, 1462 jun...
متن کاملPractical Differential Privacy in High Dimensions
Privacy-preserving, and more concretely differentially private machine learning, is concerned with hiding specific details in training datasets which contain sensitive information. Many proposed differentially private machine learning algorithms have promising theoretical properties, such as convergence to non-private performance in the limit of infinite data, computational efficiency, and poly...
متن کاملDifferentially Private Online Learning
In this paper, we consider the problem of preserving privacy in the online learning setting. Online learning involves learning from the data in real-time, so that the learned model as well as its outputs are also continuously changing. This makes preserving privacy of each data point significantly more challenging as its effect on the learned model can be easily tracked by changes in the subseq...
متن کاملDesigning a Model for Explaining and Fighting Corruption in the Private Sector, Using Grounded Theory
Many companies around the world face corruption and suffer from its negative consequences. Considering the destructive effects of corruption upon private sector enterprises, urges the need for developing a model in this area. Regarding the fact that most researches till now have been in the public sector, adds to this urgency. Thus the purpose of this study is to articulate a model for fighting...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1512.06388 شماره
صفحات -
تاریخ انتشار 2015