Learning Privacy Preserving Encodings through Adversarial Training
We present a framework to learn privacy-preserving encodings of images that inhibit inference of chosen private attributes, while allowing recovery of other desirable information. Rather than simply inhibiting a given fixed pre-trained estimator, our goal is that an estimator be unable to learn to accurately predict the private attributes even with knowledge of the encoding function. We use a natural adversarial optimization-based formulation for this---training the encoding function against a classifier for the private attribute, with both modeled as deep neural networks. The key contribution of our work is a stable and convergent optimization approach that is successful at learning an encoder with our desired properties---maintaining utility while inhibiting inference of private attributes, not just within the adversarial optimization, but also by classifiers that are trained after the encoder is fixed. We adopt a rigorous experimental protocol for verification wherein classifiers are trained exhaustively till saturation on the fixed encoders. We evaluate our approach on tasks of real-world complexity---learning high-dimensional encodings that inhibit detection of different scene categories---and find that it yields encoders that are resilient at maintaining privacy.
Code (0)
등록된 구현이 없습니다.
Tasks
AttributePrivacy PreservingSimilar Papers 제목 키워드 기반
Bounding the Invertibility of Privacy-preserving Instance Encoding using Fisher Information
Privacy-preserving instance encoding aims to encode raw data as feature vectors without revealing their privacy-sensitive information. When designed properly, these encodings can be used for downstream ML applications su…
Privacy PreservingPosthoc privacy guarantees for collaborative inference with modified Propose-Test-Release
Cloud-based machine learning inference is an emerging paradigm where users query by sending their data through a service provider who runs an ML model on that data and returns back the answer. Due to increased concerns o…
PPGAN: Privacy-preserving Generative Adversarial Network
Generative Adversarial Network (GAN) and its variants serve as a perfect representation of the data generation model, providing researchers with a large amount of high-quality generated data. They illustrate a promising …
Generative Adversarial NetworkPrivacy PreservingPrivacy-Preserving Distributed Learning in IoT Systems: A Unified Threat Model and Evaluation Framework
The increasing deployment of Internet-of-Things (IoT) devices has accelerated the use of distributed learning frameworks, where data remains local while model updates are shared across decentralized systems. Although thi…
Adversarial Attacks on Locally Private Graph Neural Networks
Graph neural network (GNN) is a powerful tool for analyzing graph-structured data. However, their vulnerability to adversarial attacks raises serious concerns, especially when dealing with sensitive information. Local Di…
Adversarial RobustnessGraph Neural NetworkGraph Learning