Privacy-Preserving Publication of Deep Neural Networks

Yuichi Sei, Hiroshi Okumura, Akihiko Ohsuga · 2016

An organization that has a lot of personal data can create a deep neural network (DNN), which predicts sensitive attribute values such as the salary and diseases of people based on other attribute values such as age and hobbies. Moreover, by putting this data on the Cloud and providing the functionality of the DNN to other organizations, they can obtain new knowledge and can subsequently create new services. However, because such DNNs are generated from sensitive attribute values, we cannot share them freely without the explicit consent of the persons whose data are used for the DNNs. On the other hand, in recent years, e-differential privacy has emerged as the de facto privacy metric. Many researchers use e-differential privacy for privacy-preserving data mining such as correlation analysis and association rule analysis. In this paper, we modify e-differential privacy for machine learning, and we propose three approaches for creating privacy-preserved DNNs based on the modified e-differential privacy. Our proposed approaches are experimentally evaluated using a real data set, and we show that our approaches can protect personal attribute values while maintaining the accuracy of the DNNs.

Read the paper · More papers on PaperTik