Towards Privacy in Deep Learning
Florian Kerschbaum · 2021
Machine learning often operates on privacy-sensitive data and this data comes with numerous threats. Differentially private learning is assumed to be the state-of-the-art coun-termeasure and many machine learning tool-kits implement differentially private gradient descent. However, we increasingly see that the protection by differentially private learning may fail and many data scientists reject it due to its large impact on model accuracy. In this paper we discuss why and how differentially private learning fails against practical privacy attacks.