[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118259-en":3,"doc-seo-118259-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118259,687197207639,"Asher","https://ap-avatar.wpscdn.com/davatar_a8503ba1806abce46bf441b54a3ca4cd",8,"Research & Report","A Novel Review of Stability Techniques for Improved Privacy-Preserving Machine Learning","Machine learning has grown rapidly in size and adoption, intensifying risks that sensitive training data may be exposed through model outputs. Privacy frameworks mitigate leakage by injecting random noise during training, but this privatization often degrades accuracy. The approach presented leverages stability: by making models less sensitive to small input or training perturbations, the required noise level can be reduced while still meeting privacy goals. The work reviews and compares stability-oriented techniques to lessen the performance cost of privacy-preserving training.","arXiv :2406 .00073v1 [ cs .LG] 31 May 2024  \nA Novel Review of Stability Techniques for Improved Privacy-Preserving Machine Learning  \nColeman DuPlessie∗ , Aidan Gao∗  \nAbstract  \nMachine learning models have recently enjoyed a significant increase in size and popularity. However, this growth has created concerns about dataset privacy. To counteract data leakage, various privacy frameworks guarantee that the output of machine learning models does not compromise their training data. However, this privatization comes at a cost by adding random noise to the training process, which reduces model performance. By making models more resistant to small changes in input and thus more stable, the necessary amount of noise can be decreased while still protecting privacy. This paper investigates various techniques to enhance stability, thereby minimizing the negative effects of privatization in machine learning.  \n1 Introduction  \nData, especially private data, has become increasingly valuable in the modern era. From hospital records to personal search histories, the increased collection and use of private data means that data analysis conducted on these data sets must protect sensitive information about individuals. Without this protection, a leak of sensitive information could easily have lasting consequences for an individual, even from seemingly innocuous data like a photo. The rise of machine learning has exacerbated these concerns even further due to its need for specific and abundant data to produce accurate predictions. This large amount of required data and machine learning models’ tendency to memorize specific yet unnecessary information, such as specific IP addresses during text responses, makes private machine learning especially important[1] .  \nReleasing models trained on private data can allow observers to extract private and personal information, compromising the algorithm’s utility. One area where this is especially important is Large Language Models (LLMs), which can often be tricked into repeating portions of their training data verbatim[2] . However, since the process of training a machine learning model is simply a (complex) algorithm that takes in training data and outputs a trained model, it is theoretically possible to privatize the machine learning process. Different mathematical frameworks underlie this privatization process, but implementing these frameworks always involves adding random noise to some steps of the training process. The traditional method, known as differential privacy (DP), adds noise to the model’s gradient during training, using the sensitivity of the training process to calculate how much noise is necessary in the theoretical, adversarial worst case. We, however, base our work on the assumption that noise will be added to parameters of the trained model, either at the end of training or at regular intervals throughout, and use a different mathematical framework, Probably Approximately Correct (PAC) privacy, that, although weaker than differential privacy in the worst case, is more flexible and still protects privacy in the majority of cases[3] .  \n* Equal contribution  \nThese frameworks, differential privacy and PAC privacy, prevent inference about characteristics of any specific data while still allowing general inferences over the whole dataset to be made[4] . By ensuring that a model follows the properties of either of these frameworks, we guarantee that including someone’s personal data in the training dataset will not result in harm, regardless of what happens to the trained model. However, the random noise necessary to ensure privacy often produces a severe loss in accuracy as a tradeoff[5] . Because the PAC framework bases the magnitude of the required noise on stability, we can ensure that privatization is minimally harmful by making the training process maximally stable. A stable model is one for which adding or removing a small amount of training data will only result in a slight ch","cbCaivcCXVn9eGfN","https://ap.wps.com/l/cbCaivcCXVn9eGfN","pdf",1871298,1,16,"English","en",105,"# Abstract\n# Introduction\n# Background\n## Privacy Mechanisms","[{\"question\":\"Why do privacy frameworks for machine learning reduce model performance?\",\"answer\":\"They protect data by adding random noise during training, and this noise creates a tradeoff that can reduce predictive accuracy.\"},{\"question\":\"How does stability help reduce the amount of noise needed for privacy?\",\"answer\":\"By making training maximally stable, small changes in training data lead to only slight changes in the final model, allowing the noise magnitude to be lowered while maintaining privacy protections.\"},{\"question\":\"What privacy notions does the paper compare?\",\"answer\":\"The paper focuses on differential privacy and PAC privacy, explaining how each uses random noise in training to prevent inference about individual data while still enabling general dataset-level learning.\"}]","A Novel Review of Stability Techniques for Improved Privacy-Preserving Machine Learning | PDF",1785682689,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"a-novel-review-of-stability-techniques-for-improved-privacy-preserving-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/a-novel-review-of-stability-techniques-for-improved-privacy-preserving-machine-learning/118259/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"Why do privacy frameworks for machine learning reduce model performance?","Question",{"text":75,"@type":76},"They protect data by adding random noise during training, and this noise creates a tradeoff that can reduce predictive accuracy.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does stability help reduce the amount of noise needed for privacy?",{"text":80,"@type":76},"By making training maximally stable, small changes in training data lead to only slight changes in the final model, allowing the noise magnitude to be lowered while maintaining privacy protections.",{"name":82,"@type":73,"acceptedAnswer":83},"What privacy notions does the paper compare?",{"text":84,"@type":76},"The paper focuses on differential privacy and PAC privacy, explaining how each uses random noise in training to prevent inference about individual data while still enabling general dataset-level learning.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":29,"slug":118},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]