arXiv · 2107.04296
Differentially private training of neural networks with Langevin dynamics for calibrated predictive uncertainty
Abstract
We show that differentially private stochastic gradient descent (DP-SGD) can yield poorly calibrated, overconfident deep learning models. This represents a serious issue for safety-critical applications, e.g. in medical diagnosis. We highlight and exploit parallels between stochastic gradient Langevin dynamics, a scalable Bayesian inference technique for training deep neural networks, and DP-SGD, in order to train differentially private, Bayesian neural networks with minor adjustments to the original (DP-SGD) algorithm. Our approach provides considerably more reliable uncertainty estimates than DP-SGD, as demonstrated empirically by a reduction in expected calibration error (MNIST $\sim{5}$-fold, Pediatric Pneumonia Dataset $\sim{2}$-fold).
Explore related subjects
Keep this discovery
Moritz Knolle, Alexander Ziller, Dmitrii Usynin, Rickmer Braren, Marcus R. Makowski, Daniel Rueckert, Georgios Kaissis. 2021-07-09. Differentially private training of neural networks with Langevin dynamics for calibrated predictive uncertainty. https://arxiv.org/abs/2107.04296
Cite the original work for its findings. Save a collection to share your selection of sources.