The Impact of Generalization Techniques on the Interplay Among Privacy, Utility, and Fairness in Image Classification
cs.LG, cs.AI
Submitted: 2024-12-16
Updated: 2024-12-16
Comments: Published as a conference paper at the 25th Privacy Enhancing Technologies Symposium (PETS 2025)
DOI: 10.56553/popets-2025-0059
Code: https://github.com/tensorflow/privacy
License: http://creativecommons.org/licenses/by/4.0/
The gist: This study investigates the trade-offs between fairness, privacy, and utility in image classification using machine learning (ML).
Terminology
Abstract
This study investigates the trade-offs between fairness, privacy, and utility in image classification using machine learning (ML). Recent research suggests that generalization techniques can improve the balance between privacy and utility. One focus of this work is sharpness-aware training (SAT) and its integration with differential privacy (DP-SAT) to further improve this balance. Additionally, we examine fairness in both private and non-private learning models trained on datasets with synthetic and real-world biases. We also measure the privacy risks involved in these scenarios by performing membership inference attacks (MIAs) and explore the consequences of eliminating high-privacy risk samples, termed outliers. Moreover, we introduce a new metric, named harmonic score, which combines accuracy, privacy, and fairness into a single measure. Through empirical analysis using generalization techniques, we achieve an accuracy of 81.11% under (8, 10-5) -DP on CIFAR-10, surpassing the 79.5% reported by De et al. (2022). Moreover, our experiments show that memorization of training samples can begin before the overfitting point, and generalization techniques do not guarantee the prevention of this memorization. Our analysis of synthetic biases shows that generalization techniques can amplify model bias in both private and non-private models. Additionally, our results indicate that increased bias in training data leads to reduced accuracy, greater vulnerability to privacy attacks, and higher model bias. We validate these findings with the CelebA dataset, demonstrating that similar trends persist with real-world attribute imbalances. Finally, our experiments show that removing outlier data decreases accuracy and further amplifies model bias.
Sources
- Efficient Sharpness-aware Minimization for Improved Training of Neural Networks
- Toward Training at ImageNet Scale with Differential Privacy
- Understanding Membership Inferences on Well-Generalized Learning Models
- R'enyi Differential Privacy of the Sampled Gaussian Mechanism
- Micro-Batch Training with Batch-Channel Normalization and Weight Standardization
- BYOL works even without batch statistics
- ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models
- Large-Scale Differentially Private BERT
- Unlocking High-Accuracy Differentially Private Image Classification through Scale
- An Empirical Analysis of Fairness Notions under Differential Privacy
- DP-SGD vs PATE: Which Has Less Disparate Impact on Model Accuracy?
- On the Importance of Difficulty Calibration in Membership Inference Attacks
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks