Differential Privacy with DP-SGD and PATE for Intrusion Detection: A Comparative Study

Daniel Machooka, Xiaohong Yuan, Kaushik Roy, Guenvere Chen · 2025

There is an increase in privacy leakage in the world of Cyber-Physical Systems. Membership inference, data reconstruction, memorization, property inference, and model stealing are exacerbated by small physical devices connected to networks where data sharing is common. Deep Learning (DL) based intrusion detection systems may have the risk of leaking sensitive training data. This research compares two privacy frameworks applied to deep learning-based intrusion detection systems for IoT network traffic. Differentially Private Stochastic Gradient Descent (DP-SGD) and Private Aggregation of Teacher Ensemble (PATE) framework are two methods for differential privacy. We compare these two methods applied in intrusion detection systems. We used two deep learning models for intrusion detection: long-short-term memory (LSTM) and multilayer perceptron (MLP). We compare these models trained under the DP-SGD and trained under the PATE framework. The performance of the model (accuracy, precision, recall, and F1) and the privacy budget were compared. The results of this study provide information on selecting differential privacy methods for detecting intrusions in cyber-physical systems.

Read the paper · More papers on PaperTik