[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118350-en":3,"doc-seo-118350-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118350,1374391975076,"Riley","https://ap-avatar.wpscdn.com/avatar/14000253ca4ec9f6853?x-image-process=image/resize,m_fixed,w_180,h_180&k=1783305029341752051",8,"Research & Report","DPMLBench - Holistic Evaluation of Differentially Private Machine Learning","Differential privacy (DP) provides a rigorous way to quantify privacy leakage, and differentially private machine learning (DPML) is increasingly used to protect sensitive data. DP-SGD remains foundational but often suffers from major utility loss, prompting many follow-up algorithms with better privacy-utility trade-offs. Prior work evaluates improvements separately and lacks holistic comparisons across utility, defensive effectiveness against membership inference attacks, and generalizability. This work performs a comprehensive benchmark on improved DPML algorithms, spanning twelve algorithms, multiple architectures and datasets, and two attack types, also covering state-of-the-art label DP methods.","VU Research Portal  \nDPMLBench  \nWei, Chengkun; Zhao, Minghu; Zhang, Zhikun; Chen, Min; Meng, Wenlong; Liu, Bo; Fan, Yuan; Chen, Wenzhi  \n2023  \nDOI (link to publisher)  \n10.48550/arXiv.2305.05900  \nLink to publication in VU Research Portal  \ncitation for published version (APA)  \nWei, C. , Zhao, M. , Zhang, Z. , Chen, M. , Meng, W. , Liu, B. , Fan, Y. , & Chen, W. (2023) . DPMLBench: Holistic Evaluation of Differentially Private Machine Learning. (pp. 1-23) . arXiv.  \n[https://doi.org/10.48550/arXiv.2305.05900](https://doi.org/10.48550/arXiv.2305.05900)  \nGeneral rights  \nCopyright and moral rights for the publications made accessible in the public portal are retained by the authors and/or other copyright owners and it is a condition of accessing publications that users recognise and abide by the legal requirements associated with these rights.  \n• Users may download and print one copy of any publication from the public portal for the purpose of private study or research.  \n• You may not further distribute the material or use it for any profit-making activity or commercial gain  \n• You may freely distribute the URL identifying the publication in the public portal  \nTake down policy  \nIf you believe that this document breaches copyright please contact us providing details, and we will remove access to the work immediately and investigate your claim.  \nE-mail address:  \n[vuresearchportal.ub@vu.nl](vuresearchportal.ub@vu.nl)  \n[Download date: 15](Download date: 15) . Feb. 2025  \nTo appear in the 30th ACM SIGSAC Conference on Computer and Communications Security. November 26-30, 2023 .  \nDPMLBench: Holistic Evaluation of Differentially Private  \nMachine Learning  \nChengkun Wei¶ * Minghu Zhao¶∗ Zhikun Zhang‡§¶† Min Chen‡ Wenlong Meng¶ Bo Liu∥ Yuan Fan¶ Wenzhi Chen¶†¶ Zhejiang University ‡ CISPA Helmholtz Center for Information Security  \n§ Stanford University ∥ DBAPPSecurity  \narXiv :2305 .05900v2 [ cs .LG] 14 Oct 2023  \nAbstract  \nDifferential privacy (DP), as a rigorous mathematical definition quantifying privacy leakage, has become a wellaccepted standard for privacy protection. Combined with powerful machine learning techniques, differentially private machine learning (DPML) is increasingly important. As the most classic DPML algorithm, DP-SGD incurs a significant loss of utility, which hinders DPML’s deployment in practice. Many studies have recently proposed improved algorithms based on DP-SGD to mitigate utility loss. However, these studies are isolated and cannot comprehensively measure the performance of improvements proposed in algorithms. More importantly, there is a lack of comprehensive research to compare improvements in these DPML algorithms across utility, defensive capabilities, and generalizability.  \nWe fill this gap by performing a holistic measurement of improved DPML algorithms on utility and defense capability against membership inference attacks (MIAs) on image classification tasks. We first present a taxonomy of where improvements are located in the machine learning life cycle. Based on our taxonomy, we jointly perform an extensive measurement study of the improved DPML algorithms, over twelve algorithms, four model architectures, four datasets, two attacks, and various privacy budget configurations. We also cover state-of-the-art label differential privacy (Label DP) algorithms in the evaluation. According to our empirical results, DP can effectively defend against MIAs, and sensitivity-bounding techniques such as per-sample gradient clipping play an important role in defense. We also explore some improvements that can maintain model utility and defend against MIAs more effectively. Experiments show that Label DP algorithms achieve less utility loss but are fragile to MIAs. Machine learning practitioners may benefit from these evaluations to select appropriate algorithms. To support our evaluation, we implement a modular re-usable software, DPMLBench, 1 which enables sensitive data owners to deploy DPML a","cbCaipCJGUsbNnip","https://ap.wps.com/l/cbCaipCJGUsbNnip","pdf",4402255,1,24,"English","en",105,"# Abstract\n# Introduction\n## Differential privacy and DPML background\n## Our Contributions","[{\"question\":\"What problem does DPMLBench address in differentially private machine learning research?\",\"answer\":\"It addresses the lack of comprehensive, holistic evaluation of improved DPML algorithms, since prior studies typically measure improvements in isolation. The goal is to compare algorithms across utility, defense against membership inference attacks, and generalizability.\"},{\"question\":\"How does DPMLBench evaluate improved DPML algorithms?\",\"answer\":\"It performs extensive measurements over twelve algorithms, four model architectures, four datasets, and two membership inference attack types under multiple privacy budget configurations. It also evaluates label differential privacy methods.\"},{\"question\":\"What key findings does the benchmark report about defense and utility?\",\"answer\":\"Experiments show that DP effectively defends against membership inference attacks, and sensitivity-bounding techniques like per-sample gradient clipping are important. Label DP approaches can reduce utility loss but may be more fragile to membership inference attacks.\"}]","DPMLBench - Holistic Evaluation of Differentially Private Machine Learning | PDF",1785683236,60,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"dpmlbench-holistic-evaluation-of-differentially-private-machine-learning","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/dpmlbench-holistic-evaluation-of-differentially-private-machine-learning/118350/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does DPMLBench address in differentially private machine learning research?","Question",{"text":75,"@type":76},"It addresses the lack of comprehensive, holistic evaluation of improved DPML algorithms, since prior studies typically measure improvements in isolation. The goal is to compare algorithms across utility, defense against membership inference attacks, and generalizability.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does DPMLBench evaluate improved DPML algorithms?",{"text":80,"@type":76},"It performs extensive measurements over twelve algorithms, four model architectures, four datasets, and two membership inference attack types under multiple privacy budget configurations. It also evaluates label differential privacy methods.",{"name":82,"@type":73,"acceptedAnswer":83},"What key findings does the benchmark report about defense and utility?",{"text":84,"@type":76},"Experiments show that DP effectively defends against membership inference attacks, and sensitivity-bounding techniques like per-sample gradient clipping are important. Label DP approaches can reduce utility loss but may be more fragile to membership inference attacks.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,109,114,119,122,127,130,134],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":29,"slug":108},5,"Comic","comic",{"id":110,"doc_module":4,"doc_module_name":46,"category_name":111,"show_sort_weight":112,"slug":113},6,"Technology",50,"technology",{"id":115,"doc_module":4,"doc_module_name":46,"category_name":116,"show_sort_weight":117,"slug":118},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":120,"slug":121},30,"research-report",{"id":123,"doc_module":4,"doc_module_name":46,"category_name":124,"show_sort_weight":125,"slug":126},9,"Religion & Spirituality",20,"religion-spirituality",{"id":125,"doc_module":4,"doc_module_name":46,"category_name":128,"show_sort_weight":125,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":46,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":46,"category_name":136,"show_sort_weight":106,"slug":137},19,"General","general"]