Training reliable deep learning models which avoid making overconfident but incorrect predictions is a longstanding challenge. This challenge is further exacerbated when learning has to be differentially private: protection provided to sensitive data comes at the price of injecting additional randomness into the learning process. In this work, we conduct a thorough empirical investigation of selective classifiers -- that can abstain when they are unsure -- under a differential privacy constraint. We find that several popular selective prediction approaches are ineffective in a differentially private setting as they increase the risk of privacy leakage. At the same time, we identify that a recent approach that only uses checkpoints produced by an off-the-shelf private learning algorithm stands out as particularly suitable under DP. Further, we show that differential privacy does not just harm utility but also degrades selective classification performance. To analyze this effect across privacy levels, we propose a novel evaluation mechanism which isolate selective prediction performance across model utility levels. Our experimental results show that recovering the performance level attainable by non-private models is possible but comes at a considerable coverage cost as the privacy budget decreases.
翻译:训练能够避免过度自信但做出错误预测的可靠深度学习模型是一个长期挑战。当学习过程需要满足差分隐私约束时,这一挑战进一步加剧:为敏感数据提供的保护是以向学习过程中注入额外随机性为代价的。本文对差分隐私约束下的选择性分类器——即在不确定时可以拒绝预测——进行了全面的实证研究。我们发现多种流行的选择性预测方法在差分隐私环境下效果不佳,因为它们会增加隐私泄露风险。同时,我们发现近期一种仅使用现成私有学习算法生成的检查点的方法,在差分隐私场景下表现出特别的适用性。进一步研究表明,差分隐私不仅损害模型效用,还会降低选择性分类性能。为分析该效应在不同隐私级别下的表现,我们提出了一种新颖的评估机制,该机制能够分离不同模型效用水平下的选择性预测性能。实验结果表明,恢复非私有模型所能达到的性能水平是可能的,但随着隐私预算降低,这一恢复需要付出显著覆盖率代价。