计算机科学
差别隐私
随机梯度下降算法
异步通信
信息隐私
泄漏(经济)
私人信息检索
数据共享
信息敏感性
信息泄露
人为噪声
数据挖掘
机器学习
深度学习
数据建模
人工智能
计算机安全
人工神经网络
计算机网络
数据库
宏观经济学
经济
医学
频道(广播)
发射机
替代医学
病理
作者
Qi Zhao,Chuan Zhao,Shujie Cui,Shan Jing,Zhenxiang Chen
摘要
Large-scale data training is vital to the generalization performance of deep learning (DL) models. However, collecting data directly is associated with increased risk of privacy disclosure, particularly in special fields such as healthcare, finance, and genomics. To protect training data privacy, collaborative deep learning (CDL) has been proposed to enable joint training from multiple data owners while providing reliable privacy guarantee. However, recent studies have shown that CDL is vulnerable to several attacks that could reveal sensitive information about the original training data. One of the most powerful attacks benefits from the leakage from gradient sharing during collaborative training process. In this study, we present a new CDL framework, PrivateDL, to effectively protect private training data against leakage from gradient sharing. Unlike conventional training process that trains on private data directly, PrivateDL allows effective transfer of relational knowledge from sensitive data to public data in a privacy-preserving way, and enables participants to jointly learn local models based on the public data with noise-preserving labels. This way, PrivateDL establishes a privacy gap between the local models and the private datasets, thereby ensuring privacy against the attacks launched to the local models through gradient sharing. Moreover, we propose a new algorithm called Distributed Aggregation Stochastic Gradient Descent, which is designed to improve the efficiency and accuracy of CDL, especially in the asynchronous training mode. Experimental results demonstrate that PrivateDL preserves data privacy with reasonable performance overhead.
科研通智能强力驱动
Strongly Powered by AbleSci AI