• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Scopus
  4. Differentially Private Prototypes for Imbalanced Transfer Learning
 
  • Details
  • Full
Options
2025
Conference Paper
Title

Differentially Private Prototypes for Imbalanced Transfer Learning

Abstract
Machine learning (ML) models have been shown to leak private information from their training datasets. Differential Privacy (DP), typically implemented through the differential private stochastic gradient descent algorithm (DP-SGD), has become the standard solution to bound leakage from the models. Despite recent improvements, DP-SGD-based approaches for private learning still usually struggle in the high privacy (ε ≤ 1) and low data regimes, and when the private training datasets are imbalanced. To overcome these limitations, we propose Differentially Private Prototype Learning (DPPL) as a new paradigm for private transfer learning. DPPL leverages publicly pre-trained encoders to extract features from private data and generates DP prototypes that represent each private class in the embedding space and can be publicly released for inference. Since our DP prototypes can be obtained from only a few private training data points and without iterative noise addition, they offer high-utility predictions and strong privacy guarantees even under the notion of pure DP. We additionally show that privacy-utility trade-offs can be further improved when leveraging the public data beyond pre-training of the encoder: in particular, we can privately sample our DP prototypes from the publicly available data points used to train the encoder. Our experimental evaluation with four state-of-the-art encoders, four vision datasets, and under different data and imbalancedness regimes demonstrate DPPL’s high performance under strong privacy guarantees in challenging private learning setups.
Author(s)
Wahdany, Dariush
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
Jagielski, Matthew
DeepMind Technologies Limited
Dziedzic, Adam
CISPA - Helmholtz Center for Information Security
Boenisch, Franziska
CISPA - Helmholtz Center for Information Security
Mainwork
39th Annual AAAI Conference on Artificial Intelligence 2025. Proceedings. No.20: AAAI-25 Technical Tracks 20  
Conference
Conference on Artificial Intelligence 2025  
Conference on Innovative Applications of Artificial Intelligence 2025  
Symposium on Educational Advances in Artificial Intelligence 2025  
Open Access
DOI
10.1609/aaai.v39i20.35395
Additional link
Full text
Language
English
Fraunhofer-Institut für Angewandte und Integrierte Sicherheit AISEC  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024