paper-with-me

Papers

Differential Privacy in Adversarial Learning with Provable Robustness

2019-09-25 · NhatHai Phan, My T. Thai, Ruoming Jin, Han Hu, Dejing Dou

In this paper, we aim to develop a novel mechanism to preserve differential privacy (DP) in adversarial learning for deep neural networks, with provable robustness to adversarial examples. We leverage the sequential composition theory in DP, to establish a new connection between DP preservation and provable robustness. To address the trade-off among model utility, privacy loss, and robustness, we design an original, differentially private, adversarial objective function, based on the post-processing property in DP, to tighten the sensitivity of our model. An end-to-end theoretical analysis and thorough evaluations show that our mechanism notably improves the robustness of DP deep neural networks.

📄 PDF Abstract BibTeX

Code (0)

등록된 구현이 없습니다.

Tasks

Sensitivity

Similar Papers 제목 키워드 기반

Heterogeneous Gaussian Mechanism: Preserving Differential Privacy in Deep Learning with Provable Robustness

2019-06-02 · NhatHai Phan, Minh Vu, Yang Liu, Ruoming Jin 외

In this paper, we propose a novel Heterogeneous Gaussian Mechanism (HGM) to preserve differential privacy in deep neural networks, with provable robustness against adversarial examples. We first relax the constraint of t…

Provable Robustness against Backdoor Attacks via the Primal-Dual Perspective on Differential Privacy

2026-05-20 · Aman Saxena, Jan Schuchardt, Yan Scholten, Stephan Günnemann arxiv

Randomized smoothing is a powerful tool for certifying robustness to adversarial perturbations, including poisoning attacks via randomized training and evasion attacks via randomized inference. Extending these guarantees…

Certified Robustness to Word Substitution Attack with Differential Privacy

2021-06-01 · NAACL 2021 4 · Wenjie Wang, Pengfei Tang, Jian Lou, Li Xiong

The robustness and security of natural language processing (NLP) models are significantly important in real-world applications. In the context of text classification tasks, adversarial examples can be designed by substit…

Adversarial RobustnessClassificationtext-classificationText Classification

Abstract Gradient Training: A Unified Certification Framework for Data Poisoning, Unlearning, and Differential Privacy

2025-11-12 · Philip Sosnin, Matthew Wicker, Josh Collyer, Calvin Tsay arxiv

The impact of inference-time data perturbation (e.g., adversarial attacks) has been extensively studied in machine learning, leading to well-established certification techniques for adversarial robustness. In contrast, c…

Adversarial Robustness

Certifiably Robust Interpretation via Renyi Differential Privacy

2021-07-04 · Ao Liu, Xiaoyu Chen, Sijia Liu, Lirong Xia 외

Motivated by the recent discovery that the interpretation maps of CNNs could easily be manipulated by adversarial attacks against network interpretability, we study the problem of interpretation robustness from a new per…

Computational Efficiency