arXiv Machine Learning
Jul 23

Differentially Private Neural Network Training Under the Hidden State Assumption

arXiv:2407. 08233v3 Announce Type: replace Abstract: Current differentially private learning paradigms face a severe utility bottleneck: DP-SGD degrades performance through noise accumulation over training steps, while aggregation-based approaches such as PATE suffer from data inefficiency due to disjoint data partitioning.

By Ding Chen, Haochen Luo, Xiaofei Wang, Chen Liu
arXiv Machine Learning
5d ago

Differentially-Private Decision Trees and Provable Robustness to Data Poisoning

The paper introduces PrivaTree, a differentially‑private decision tree algorithm that uses private histograms to select splits while preserving a small privacy budget. PrivaTree supports mixed numerical and categorical data without leaking information about numerical features and achieves a superior privacy‑utility trade‑off compared to existing methods. Additionally, the authors provide theoretical bounds on the expected accuracy and success rates of backdoor attacks, showing that PrivaTree-trained trees are more robust against data poisoning than standard decision trees.

By Dani\"el Vos, Jelle Vos, Tianyu Li, Zekeriya Erkin, Sicco Verwer