InstaHide: Instance-hiding Schemes for Private Distributed Learning

How can multiple distributed entities collaboratively train a shared deep net on their private data while preserving privacy? This paper introduces InstaHide, a simple encryption of training images, which can be plugged into existing distributed deep learning pipelines. The encryption is efficient and applying it during training has minor effect on test accuracy. InstaHide encrypts each training image with a "one-time secret key" which consists of mixing a number of randomly chosen images and applying a random pixel-wise mask. Other contributions of this paper include: (a) Using a large public dataset (e.g. ImageNet) for mixing during its encryption, which improves security. (b) Experimental results to show effectiveness in preserving privacy against known attacks with only minor effects on accuracy. (c) Theoretical analysis showing that successfully attacking privacy requires attackers to solve a difficult computational problem. (d) Demonstrating that use of the pixel-wise mask is important for security, since Mixup alone is shown to be insecure to some some efficient attacks. (e) Release of a challenge dataset https://github.com/Hazelsuko07/InstaHide_Challenge Our code is available at https://github.com/Hazelsuko07/InstaHide

Image qualityassessment: from error…Image quality assessment: from error visibility to structural similarityCompressed sensingCompressed sensingStable signal recoveryfrom incomplete and…Stable signal recovery from incomplete and inaccurate measurementsImageNet: A large-scalehierarchical image…ImageNet: A large-scale hierarchical image databaseVery Deep ConvolutionalNetworks for Large-Scal…Very Deep Convolutional Networks for Large-Scale Image RecognitionDeep Residual Learningfor Image RecognitionDeep Residual Learning for Image RecognitionDeep Learning withDifferential PrivacyDeep Learning with Differential PrivacyAggregated ResidualTransformations for Dee…Aggregated Residual Transformations for Deep Neural NetworksMulti-keyprivacy-preserving deep…Multi-key privacy-preserving deep learning in cloud computingPyTorch: An ImperativeStyle, High-Performance…PyTorch: An Imperative Style, High-Performance Deep Learning LibraryAn Attack on InstaHide:Is Private Learning…An Attack on InstaHide: Is Private Learning Possible with Instance Encoding?Learning Multiple Layersof Features from Tiny…Learning Multiple Layers of Features from Tiny ImagesCaPC Learning:Confidential and Privat…CaPC Learning: Confidential and Private Collaborative LearningQuantum federatedlearning through blind…Quantum federated learning through blind quantum computingA Fusion-DenoisingAttack on InstaHide wit…A Fusion-Denoising Attack on InstaHide with Data AugmentationAppClassNet: acommercial-grade datase…AppClassNet: a commercial-grade dataset for application identification researchPrivacy-Preserving ImageClassification Using…Privacy-Preserving Image Classification Using ConvMixer with Adaptative Permutation Matrix and Block-Wise Scrambled Image EncryptionDropout Is NOT All YouNeed to Prevent Gradien…Dropout Is NOT All You Need to Prevent Gradient LeakageRAI2: ResponsibleIdentity Audit Governin…RAI2: Responsible Identity Audit Governing the Artificial IntelligenceYou Can Use But CannotRecognize: Preserving…You Can Use But Cannot Recognize: Preserving Visual Privacy in Deep Neural NetworksHigh-Fidelity GradientInversion in Distribute…High-Fidelity Gradient Inversion in Distributed LearningConcealing SensitiveSamples against Gradien…Concealing Sensitive Samples against Gradient Leakage in Federated LearningPPIDSG: APrivacy-Preserving Imag…PPIDSG: A Privacy-Preserving Image Distribution Sharing Scheme with GAN in Federated LearningHuman-UnrecognizableDifferential Private…Human-Unrecognizable Differential Private Noised Image Generation MethodInstaHide:Instance-hiding Schemes…InstaHide: Instance-hiding Schemes for Private Distributed LearningEarlier referencesFocus paperCiting papersOlderNewer

Click a node to pin it, click the empty canvas to go back to this paper, or hover to preview. Open a node’s page from its title.