"Private Prediction Strikes Back!” Private Kernelized Nearest Neighbors with Individual Renyi Filter

06/12/2023
by   Yuqing Zhu, et al.
0

Most existing approaches of differentially private (DP) machine learning focus on private training. Despite its many advantages, private training lacks the flexibility in adapting to incremental changes to the training dataset such as deletion requests from exercising GDPR's right to be forgotten. We revisit a long-forgotten alternative, known as private prediction, and propose a new algorithm named Individual Kernelized Nearest Neighbor (Ind-KNN). Ind-KNN is easily updatable over dataset changes and it allows precise control of the Rényi DP at an individual user level – a user's privacy loss is measured by the exact amount of her contribution to predictions; and a user is removed if her prescribed privacy budget runs out. Our results show that Ind-KNN consistently improves the accuracy over existing private prediction methods for a wide range of ϵ on four vision and language tasks. We also illustrate several cases under which Ind-KNN is preferable over private training with NoisySGD.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
05/02/2023

Differentially Private In-Context Learning

An important question in deploying large language models (LLMs) is how t...
research
01/07/2023

k-Means SubClustering: A Differentially Private Algorithm with Improved Clustering Quality

In today's data-driven world, the sensitivity of information has been a ...
research
09/04/2019

Privacy Accounting and Quality Control in the Sage Differentially Private ML Platform

Companies increasingly expose machine learning (ML) models trained over ...
research
10/15/2022

A Closer Look at the Calibration of Differentially Private Learners

We systematically study the calibration of classifiers trained with diff...
research
06/02/2023

Harnessing large-language models to generate private synthetic text

Differentially private (DP) training methods like DP-SGD can protect sen...
research
10/04/2022

Recycling Scraps: Improving Private Learning by Leveraging Intermediate Checkpoints

All state-of-the-art (SOTA) differentially private machine learning (DP ...
research
04/16/2021

Achieving differential privacy for k-nearest neighbors based outlier detection by data partitioning

When applying outlier detection in settings where data is sensitive, mec...

Please sign up or login with your details

Forgot password? Click here to reset