PrivEdge: from local to distributed private training and prediction
File(s)2004.05574v1.pdf (3.9 MB)
Accepted version
Author(s)
Shamsabadi, Ali Shahin
Gascon, Adria
Haddadi, Hamed
Cavallaro, Andrea
Type
Journal Article
Abstract
Machine Learning as a Service (MLaaS) operators provide model training and prediction on the cloud. MLaaS applications often rely on centralised collection and aggregation of user data, which could lead to significant privacy concerns when dealing with sensitive personal data. To address this problem, we propose PrivEdge, a technique for privacy-preserving MLaaS that safeguards the privacy of users who provide their data for training, as well as users who use the prediction service. With PrivEdge, each user independently uses their private data to locally train a one-class reconstructive adversarial network that succinctly represents their training data. As sending the model parameters to the service provider in the clear would reveal private information, PrivEdge secret-shares the parameters among two non-colluding MLaaS providers, to then provide cryptographically private prediction services through secure multi-party computation techniques. We quantify the benefits of PrivEdge and compare its performance with state-of-the-art centralised architectures on three privacy-sensitive image-based tasks: individual identification, writer identification, and handwritten letter recognition. Experimental results show that PrivEdge has high precision and recall in preserving privacy, as well as in distinguishing between private and non-private images. Moreover, we show the robustness of PrivEdge to image compression and biased training data. The source code is available at https://github.com/smartcameras/PrivEdge.
Date Issued
2020-04-16
Date Acceptance
2020-03-27
Citation
IEEE Transactions on Information Forensics and Security, 2020, 15 (1), pp.3819-3831
ISSN
1556-6013
Publisher
Institute of Electrical and Electronics Engineers
Start Page
3819
End Page
3831
Journal / Book Title
IEEE Transactions on Information Forensics and Security
Volume
15
Issue
1
Copyright Statement
© 2020 The Author(s)
© 2020 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, in any current or future media, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works, for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.
Sponsor
Engineering & Physical Science Research Council (EPSRC)
Engineering & Physical Science Research Council (E
Engineering & Physical Science Research Council (E
Identifier
http://arxiv.org/abs/2004.05574v1
Grant Number
EP/N028260/2
RGS128099 (EP/R03351X/1)
PO: 20177802 (Ref: 301671)
Subjects
cs.CR
cs.CR
cs.LG
Notes
IEEE Transactions on Information Forensics and Security (TIFS)
Publication Status
Published
Date Publish Online
2020-04-16