Empirical evaluation of amplifying privacy by subsampling for GANs to create differentially private synthetic tabular data

dc.contributor.authorNieminen Valtteri A.
dc.contributor.authorPahikkala Tapio
dc.contributor.authorAirola Antti
dc.contributor.organizationfi=data-analytiikka|en=Data-analytiikka|
dc.contributor.organizationfi=terveysteknologia|en=Health Technology|
dc.contributor.organization-code1.2.246.10.2458963.20.28696315432
dc.contributor.organization-code1.2.246.10.2458963.20.68940835793
dc.converis.publication-id181712336
dc.converis.urlhttps://research.utu.fi/converis/portal/Publication/181712336
dc.date.accessioned2025-08-28T01:25:41Z
dc.date.available2025-08-28T01:25:41Z
dc.description.abstract<p>Privacy concerns often limit sharing sensitive data collected from individuals. One proposed solution to make secondary use possible is privacy-preserving synthetic data that attempts to mimic real data. Due to their success on non-private tasks, GAN networks trained with differentially private stochastic gradient descent (DPSGD) have been popular for generating DP synthetic data. In recent years, a prominent approach to achieving better privacy guarantees has been to train ensembles of discriminator networks with DPSDG on mutually exclusive subsets to obtain better differential privacy guarantees by taking advantage of the synergy between GANs and privacy amplification by subsampling. However, this research has been done almost exclusively on images, and empirical evaluations of this strategy on other types of data are lacking. This work focuses on the effects of subsampling in creating DP synthetic tabular data with GANs. We evaluate synthetic data utility by training classification models on synthetic- and testing on real data at varying subsampling rates. Further, we complement the evaluation with a qualitative examination of the generated data. Our findings show that while subsampling does bring benefits with tabular data in terms of the prediction performance for classifiers trained on synthetic data, the resulting samples can be very distorted compared to original real data. The results suggest that the benefits obtainable via this method of training DP GAN can differ significantly based on the type of data used.</p>
dc.format.pagerange72
dc.format.pagerange81
dc.identifier.issn1613-0073
dc.identifier.jour-issn1613-0073
dc.identifier.olddbid207539
dc.identifier.oldhandle10024/190566
dc.identifier.urihttps://www.utupub.fi/handle/11111/52269
dc.identifier.urlhttps://ceur-ws.org/Vol-3506/
dc.identifier.urnURN:NBN:fi-fe2025082787704
dc.language.isoen
dc.okm.affiliatedauthorNieminen, Valtteri
dc.okm.affiliatedauthorPahikkala, Tapio
dc.okm.affiliatedauthorAirola, Antti
dc.okm.discipline113 Computer and information sciencesen_GB
dc.okm.discipline113 Tietojenkäsittely ja informaatiotieteetfi_FI
dc.okm.internationalcopublicationnot an international co-publication
dc.okm.internationalityInternational publication
dc.okm.typeA4 Conference Article
dc.publisher.countryGermanyen_GB
dc.publisher.countrySaksafi_FI
dc.publisher.country-codeDE
dc.relation.conferenceAnnual Symposium for Computer Science
dc.relation.ispartofjournalCEUR Workshop Proceedings
dc.relation.ispartofseriesCEUR Workshop Proceedings
dc.relation.volume3506
dc.source.identifierhttps://www.utupub.fi/handle/10024/190566
dc.titleEmpirical evaluation of amplifying privacy by subsampling for GANs to create differentially private synthetic tabular data
dc.title.bookTKTP 2023: Annual Symposium for Computer Science 2023: Proceedings of the 40th Anniversary Symposium of the Finnish Society for Computer Science
dc.year.issued2023

Tiedostot

Näytetään 1 - 1 / 1
Ladataan...
Name:
paper06.pdf
Size:
2.6 MB
Format:
Adobe Portable Document Format