Protection Against Reconstruction and Its Applications in Private Federated Learning
Abhishek Bhowmick Affiliation: ML Privacy Team, Apple, Inc. John Duchi Affiliation: ML Privacy Team, Apple, Inc. Affiliation: Stanford University Julien Freudiger Affiliation: ML Privacy Team, Apple, Inc. Gaurav Kapoor Affiliation: ML Privacy Team, Apple, Inc. Ryan Rogers Affiliation: ML Privacy Team, Apple, Inc.
Abstract
In large-scale statistical learning, data collection and model fitting are moving increasingly toward peripheral devices—phones, watches, fitness trackers—away from centralized data collection. Concomitant with this rise in decentralized data are increasing challenges of maintaining privacy while allowing enough information to fit accurate, useful statistical models. This motivates local notions of privacy—most significantly, local differential privacy, which provides strong protections against sensitive data disclosures—where data is obfuscated before a statistician or learner can even observe it, providing strong protections to individuals’ data. Yet local privacy as traditionally employed may prove too stringent for practical use, especially in modern high-dimensional statistical and machine learning problems. Consequently, we revisit the types of disclosures and adversaries against which we provide protections, considering adversaries with limited prior information and ensuring that with high probability, ensuring they cannot reconstruct an individual’s data within useful tolerances. By reconceptualizing these protections, we allow more useful data release—large privacy paramet
原文 arXiv:1812.00984;中英对照 + 大白话阅读 https://aha.fim.ai/paper/1812.00984v2