Current browse context:
cs.LG
Change to browse by:
References & Citations
Computer Science > Machine Learning
Title: Gaussian Processes with Differential Privacy
(Submitted on 1 Jun 2021 (v1), last revised 11 Nov 2021 (this version, v2))
Abstract: Gaussian processes (GPs) are non-parametric Bayesian models that are widely used for diverse prediction tasks. Previous work in adding strong privacy protection to GPs via differential privacy (DP) has been limited to protecting only the privacy of the prediction targets (model outputs) but not inputs. We break this limitation by introducing GPs with DP protection for both model inputs and outputs. We achieve this by using sparse GP methodology and publishing a private variational approximation on known inducing points. The approximation covariance is adjusted to approximately account for the added uncertainty from DP noise. The approximation can be used to compute arbitrary predictions using standard sparse GP techniques. We propose a method for hyperparameter learning using a private selection protocol applied to validation set log-likelihood. Our experiments demonstrate that given sufficient amount of data, the method can produce accurate models under strong privacy protection.
Submission history
From: Antti Honkela [view email][v1] Tue, 1 Jun 2021 13:23:16 GMT (60kb,D)
[v2] Thu, 11 Nov 2021 12:03:26 GMT (72kb,D)
Link back to: arXiv, form interface, contact.