paper-with-me

Papers

InstaHide's Sample Complexity When Mixing Two Private Images

2020-11-24 · Baihe Huang, Zhao Song, Runzhou Tao, Junze Yin, Ruizhe Zhang, Danyang Zhuo

Training neural networks usually require large numbers of sensitive training data, and how to protect the privacy of training data has thus become a critical topic in deep learning research. InstaHide is a state-of-the-art scheme to protect training data privacy with only minor effects on test accuracy, and its security has become a salient question. In this paper, we systematically study recent attacks on InstaHide and present a unified framework to understand and analyze these attacks. We find that existing attacks either do not have a provable guarantee or can only recover a single private image. On the current InstaHide challenge setup, where each InstaHide image is a mixture of two private images, we present a new algorithm to recover all the private images with a provable guarantee and optimal sample complexity. In addition, we also provide a computational hardness result on retrieving all InstaHide images. Our results demonstrate that InstaHide is not information-theoretically secure but computationally secure in the worst case, even when mixing two private images.

📄 PDF Abstract BibTeX arXiv:2011.11877

Code (0)

등록된 구현이 없습니다.

Tasks

Vocal Bursts Valence Prediction

Similar Papers 제목 키워드 기반

InstaHide’s Sample Complexity When Mixing Two Private Images

2021-09-29 · Baihe Huang, Zhao Song, Runzhou Tao, Ruizhe Zhang 외

Inspired by InstaHide challenge [Huang, Song, Li and Arora'20], [Chen, Song and Zhuo'20] recently provides one mathematical formulation of InstaHide attack problem under Gaussian images distribution. They show that it su…

Vocal Bursts Valence Prediction

A Fusion-Denoising Attack on InstaHide with Data Augmentation

2021-05-17 · Xinjian Luo, Xiaokui Xiao, Yuncheng Wu, Juncheng Liu 외

InstaHide is a state-of-the-art mechanism for protecting private training images, by mixing multiple private images and modifying them such that their visual features are indistinguishable to the naked eye. In recent wor…

Data AugmentationDenoising

InstaHide: Instance-hiding Schemes for Private Distributed Learning

2020-10-06 · Yangsibo Huang, Zhao Song, Kai Li, Sanjeev Arora

How can multiple distributed entities collaboratively train a shared deep net on their private data while preserving privacy? This paper introduces InstaHide, a simple encryption of training images, which can be plugged …

On InstaHide, Phase Retrieval, and Sparse Matrix Factorization

2020-11-23 · Sitan Chen, Xiaoxiao Li, Zhao Song, Danyang Zhuo

In this work, we examine the security of InstaHide, a scheme recently proposed by [Huang, Song, Li and Arora, ICML'20] for preserving the security of private datasets in the context of distributed learning. To generate a…

Retrieval

What Can Phase Retrieval Tell Us About Private Distributed Learning?

2021-01-01 · ICLR 2021 1 · Sitan Chen, Xiaoxiao Li, Zhao Song, Danyang Zhuo

In this work, we examine the security of InstaHide, a scheme recently proposed by \cite{hsla20} for preserving the security of private datasets in the context of distributed learning. To generate a synthetic training exa…

Retrieval