English

Rethinking Privacy Preserving Deep Learning: How to Evaluate and Thwart Privacy Attacks

Machine Learning 2020-06-25 v2 Cryptography and Security Distributed, Parallel, and Cluster Computing Machine Learning

Abstract

This paper investigates capabilities of Privacy-Preserving Deep Learning (PPDL) mechanisms against various forms of privacy attacks. First, we propose to quantitatively measure the trade-off between model accuracy and privacy losses incurred by reconstruction, tracing and membership attacks. Second, we formulate reconstruction attacks as solving a noisy system of linear equations, and prove that attacks are guaranteed to be defeated if condition (2) is unfulfilled. Third, based on theoretical analysis, a novel Secret Polarization Network (SPN) is proposed to thwart privacy attacks, which pose serious challenges to existing PPDL methods. Extensive experiments showed that model accuracies are improved on average by 5-20% compared with baseline mechanisms, in regimes where data privacy are satisfactorily protected.

Keywords

Cite

@article{arxiv.2006.11601,
  title  = {Rethinking Privacy Preserving Deep Learning: How to Evaluate and Thwart Privacy Attacks},
  author = {Lixin Fan and Kam Woh Ng and Ce Ju and Tianyu Zhang and Chang Liu and Chee Seng Chan and Qiang Yang},
  journal= {arXiv preprint arXiv:2006.11601},
  year   = {2020}
}

Comments

under review, 36 pages (updated Eq. 3 and Fig. 8)

R2 v1 2026-06-23T16:29:14.053Z