← 返回论文检索
ICML 2024PosterAccept (Oral)

Position: Considerations for Differentially Private Learning with Large-Scale Public Pretraining

Florian Tramer, Gautam Kamath, Nicholas Carlini

ETH Zürich · University of Waterloo · Google DeepMind

PDF 由论文原始站点提供,PaperCompass 不保存论文文件。

摘要

The performance of differentially private machine learning can be boosted significantly by leveraging the transfer learning capabilities of non-private models pretrained on large *public* datasets. We critically review this approach. We primarily question whether the use of large Web-scraped datasets *should* be viewed as differential-privacy-preserving. We further scrutinize whether existing machine learning benchmarks are appropriate for measuring the ability of pretrained models to generalize to sensitive domains. Finally, we observe that reliance on large pretrained models may lose *other* forms of privacy, requiring data to be outsourced to a more compute-powerful third party.