arXiv · 2408.05723
Deep Learning with Data Privacy via Residual Perturbation
Abstract
Protecting data privacy in deep learning (DL) is of crucial importance. Several celebrated privacy notions have been established and used for privacy-preserving DL. However, many existing mechanisms achieve privacy at the cost of significant utility degradation and computational overhead. In this paper, we propose a stochastic differential equation-based residual perturbation for privacy-preserving DL, which injects Gaussian noise into each residual mapping of ResNets. Theoretically, we prove that residual perturbation guarantees differential privacy (DP) and reduces the generalization gap of DL. Empirically, we show that residual perturbation is computationally efficient and outperforms the state-of-the-art differentially private stochastic gradient descent (DPSGD) in utility maintenance without sacrificing membership privacy.
Explore related subjects
Keep this discovery
Wenqi Tao, Huaming Ling, Zuoqiang Shi, Bao Wang. 2024-08-11. Deep Learning with Data Privacy via Residual Perturbation. https://arxiv.org/abs/2408.05723
Cite the original work for its findings. Save a collection to share your selection of sources.