GAN-Based Privacy-Preserving Unsupervised Domain Adaptation
Dongdong Zhao, Zhao Wang, Huanhuan Li, Jianwen Xiang · 2022
In recent years, the rapid development of deep learning is attributed to the large amount of labeled data brought by the digital age. When there is no labeled data available in some application scenarios, domain adaptation can be used to transfer knowledge from the source domain with labeled data to the target domain without labeled data. In the process of domain adaptation, the target client requires direct access to the source data or model, which would lead to the risk of privacy leakage, e.g., Membership Inference Attacks (MIA). Attackers can collect the prediction vector of the model through black-box access to the source model, and then infer an individual’s membership in the source training dataset. To deal with this privacy issue, we propose a GAN-based Privacy-Preserving Unsupervised Domain Adaptation Framework. Specifically, the target client learns a conditional generator, sends the intermediate results perturbed by differential privacy to the source client, and the source client uses the source model to provide guidance for the generator so that the generator can generate the data corresponding to the input label that is the same as the data distribution in the target domain. We evaluate the performance of our proposed method on digital dataset and office-31dataset, which are popular domain adaptation benchmark datasets, and verify the security by the accuracy and F1-score of Membership Inference Attacks.