Granularity is crucial when applying differential privacy to text: An investigation for neural machine translation
Vu, Doan Nam Long, Igamberdiev, Timour, Habernal, Ivan
–arXiv.org Artificial Intelligence
Applying differential privacy (DP) by means of the DP-SGD algorithm to protect individual data points during training is becoming increasingly popular in NLP. However, the choice of granularity at which DP is applied is often neglected. For example, neural machine translation (NMT) typically operates on the sentence-level granularity. From the perspective of DP, this setup assumes that each sentence belongs to a single person and any two sentences in the training dataset are independent. This assumption is however violated in many real-world NMT datasets, e.g. those including dialogues. For proper application of DP we thus must shift from sentences to entire documents. In this paper, we investigate NMT at both the sentence and document levels, analyzing the privacy/utility trade-off for both scenarios, and evaluating the risks of not using the appropriate privacy granularity in terms of leaking personally identifiable information (PII). Our findings indicate that the document-level NMT system is more resistant to membership inference attacks, emphasizing the significance of using the appropriate granularity when working with DP.
arXiv.org Artificial Intelligence
Jul-26-2024
- Country:
- South America > Chile
- North America
- United States
- Pennsylvania (0.04)
- Washington > King County
- Seattle (0.04)
- California
- Santa Clara County > Santa Clara (0.04)
- Santa Barbara County > Santa Barbara (0.04)
- Canada > Ontario
- Toronto (0.04)
- United States
- Europe
- Middle East > Malta (0.04)
- Ireland > Leinster
- County Dublin > Dublin (0.04)
- Germany > Hesse
- Darmstadt Region > Darmstadt (0.04)
- Croatia > Dubrovnik-Neretva County
- Dubrovnik (0.04)
- Belgium > Brussels-Capital Region
- Brussels (0.04)
- Asia
- Singapore (0.04)
- China > Hong Kong (0.04)
- Thailand > Phuket
- Phuket (0.04)
- Middle East > UAE
- Abu Dhabi Emirate > Abu Dhabi (0.14)
- Genre:
- Research Report > New Finding (0.66)
- Industry:
- Information Technology > Security & Privacy (1.00)
- Technology: