Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml Jakob Voss, based on art designer at PLoS, modified by Wikipedia users Nina and Beao Closed Access logo, derived from PLoS Open Access logo. This version with transparent background. http://commons.wikimedia.org/wiki/File:Closed_Access_logo_transparent.svg Jakob Voss, based on art designer at PLoS, modified by Wikipedia users Nina and Beao https://doi.org/10.1...arrow_drop_down
image/svg+xml Jakob Voss, based on art designer at PLoS, modified by Wikipedia users Nina and Beao Closed Access logo, derived from PLoS Open Access logo. This version with transparent background. http://commons.wikimedia.org/wiki/File:Closed_Access_logo_transparent.svg Jakob Voss, based on art designer at PLoS, modified by Wikipedia users Nina and Beao
https://doi.org/10.1007/978-3-...
Part of book or chapter of book . 2020 . Peer-reviewed
License: Springer TDM
Data sources: Crossref
versions View all 1 versions
addClaim

This Research product is the result of merged Research products in OpenAIRE.

You have already added 0 works in your ORCID record related to the merged Research product.

Deep Learning Algorithms Design and Implementation Based on Differential Privacy

Authors: Xuefeng Xu; Yanqing Yao; Lei Cheng;

Deep Learning Algorithms Design and Implementation Based on Differential Privacy

Abstract

Deep learning models bear the risks of privacy leakage. Attackers can obtain sensitive information contained in training data with some techniques. However, existing differentially private methods such as Differential Privacy-Stochastic Gradient Descent (DP-SGD) and Differential Privacy-Generative Adversarial Network (DP-GAN) are not very efficient as they require to perform sampling multiple times. More importantly, DP-GAN algorithm need public data to set gradient clipping threshold. In this paper, we introduce our refined algorithms to tackle these problems. First, we employ random shuffling instead of random sampling to improve training efficiency. We also test Gaussian and Laplace Mechanisms for clipping gradients and injecting noise. Second, we employ zero Concentrated Differential Privacy (zCDP) to compute overall privacy budget. Finally, we adopt dynamical gradient clipping in DP-GAN algorithm. During each iteration, we random sample training examples and set the average gradients norm as the new threshold. This not only makes the algorithm more robust but also doesn’t increase the overall privacy budget. We experiment with our algorithms on MNIST data sets and demonstrate the accuracies. In our refined DP-SGD algorithm, we achieve test accuracy of 96.58%. In our refined DP-GAN algorithm, we adopt the synthetic data to train models and reach test accuracy of 91.64%. The results show that our approach ensures model usability and provides the capability of privacy protection.

Related Organizations
  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    1
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
1
Average
Average
Average
Upload OA version
Are you the author of this publication? Upload your Open Access version to Zenodo!
It’s fast and easy, just two clicks!