Deep Learning with Label Differential Privacy
Badih Ghazi, Noah Golowich, Ravi Kumar, Pasin Manurangsi, Chiyuan Zhang
Abstract
The Randomized Response (RR) algorithm [96] is a classical technique to improve robustness in survey aggregation, and has been widely adopted in applications with differential privacy guarantees. We propose a novel algorithm, Randomized Response with Prior (RRWithPrior), which can provide more accurate results while maintaining the same level of privacy guaranteed by RR. We then apply RRWithPrior to learn neural networks with label differential privacy (Labe DP), and show that when only the label needs to be protected, the model performance can be significantly improved over the previous state-of-the-art private baselines. Moreover, we study different ways to obtain priors, which when used with RRWithPrior can additionally improve the model performance, further reducing the accuracy gap between private and non-private models. We complement the empirical results with theoretical analysis showing that Labe DP is provably easier than protecting both the inputs and labels.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3fa9ad53-842b-4f62-94ba-7e6630d1fa6dCited by top-tier papers41
- On Provable Copyright Protection for Generative ModelsNikhil Vyas, Sham M. Kakade, Boaz BarakICML 2023 · 120 citations
- MergeSFL: Split Federated Learning with Feature Merging and Batch Size RegulationYunming Liao, Yang Xu, Hongli Xu, Lun Wang et al.ICDE 2024 · 41 citations
- DP-Forward: Fine-tuning and Inference on Language Models with Differential Privacy in Forward PassMinxin Du, Xiang Yue, Sherman S. M. Chow, Tianhao Wang et al.CCS 2023 · 35 citations
- Just Fine-tune Twice: Selective Differential Privacy for Large Language ModelsWeiyan Shi, Ryan Shea, Si Chen, Chiyuan Zhang et al.EMNLP 2022 · 34 citations
- Weak Proxies are Sufficient and Preferable for Fairness with Missing Sensitive AttributesZhaowei Zhu, Yuanshun Yao, Jiankai Sun, Hang Li et al.ICML 2023 · 28 citations
Builds on27
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- Bootstrap Your Own Latent - A New Approach to Self-Supervised LearningJean-Bastien Grill, Florian Strub, Florent Altché, Corentin Tallec et al.NeurIPS 2020 · 9,171 citations
- Emerging Properties in Self-Supervised Vision TransformersMathilde Caron, Hugo Touvron, Ishan Misra, Hervé Jégou et al.ICCV 2021 · 8,921 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Big Self-Supervised Models are Strong Semi-Supervised LearnersTing Chen, Simon Kornblith, Kevin Swersky, Mohammad Norouzi et al.NeurIPS 2020 · 2,611 citations
Related papers
- LabelDP-Pro: Learning with Label Differential Privacy via ProjectionsBadih Ghazi, Yangsibo Huang, Pritish Kamath, Ravi Kumar et al.ICLR 2024 · 4 citations
- Optimal Unbiased Randomizers for Regression with Label Differential PrivacyAshwinkumar Badanidiyuru Varadaraja, Badih Ghazi, Pritish Kamath, Ravi Kumar et al.NeurIPS 2023 · 9 citations
- Federated Latent Dirichlet Allocation: A Local Differential Privacy Based FrameworkYansheng Wang, Yongxin Tong, Dingyuan ShiAAAI 2020 · 128 citations
- Regression with Label Differential PrivacyBadih Ghazi, Pritish Kamath, Ravi Kumar, Ethan Leeman et al.ICLR 2023
- GAP: Differentially Private Graph Neural Networks with Aggregation PerturbationSina Sajadmanesh, Ali Shahin Shamsabadi, Aurélien Bellet, Daniel Gatica-PerezUSENIX Security 2023
