A unified view on differential privacy and robustness to adversarial examples - Département Métrologie Instrumentation & Information Accéder directement au contenu
Communication Dans Un Congrès Année : 2019

A unified view on differential privacy and robustness to adversarial examples

Résumé

This short note highlights some links between two lines of research within the emerging topic of trustworthy machine learning: differential privacy and robustness to adversarial examples. By abstracting the definitions of both notions, we show that they build upon the same theoretical ground and hence results obtained so far in one domain can be transferred to the other. More precisely, our analysis is based on two key elements: probabilistic mappings (also called randomized algorithms in the differential privacy community), and the Renyi divergence which subsumes a large family of divergences. We first generalize the definition of robustness against adversarial examples to encompass probabilistic mappings. Then we observe that Renyi-differential privacy (a generalization of differential privacy recently proposed in [10]) and our definition of robustness share several similarities. We finally discuss how can both communities benefit from this connection to transfer technical tools from one research field to the other.
Fichier principal
Vignette du fichier
1906.07982.pdf (134.65 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

hal-02892170 , version 1 (07-07-2020)

Identifiants

  • HAL Id : hal-02892170 , version 1

Citer

Rafael Pinot, Florian Yger, Cedric Gouy-Pailler, Jamal Atif. A unified view on differential privacy and robustness to adversarial examples. Workshop on Machine Learning for CyberSecurity at ECMLPKDD 2019, Sep 2019, Wurzburg, Germany. ⟨hal-02892170⟩
144 Consultations
476 Téléchargements

Partager

Gmail Facebook X LinkedIn More